CVE-2026-53343
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/07/2026
Last modified:
23/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow<br />
<br />
Commit 44e9a3bb76e5 ("ARM: 9430/1: entry: Do a dummy read from<br />
VMAP shadow") added a dummy read from the KASAN VMAP stack shadow in<br />
__switch_to(). The read uses ldr, but the KASAN shadow address is<br />
byte-granular and is not guaranteed to be word aligned.<br />
<br />
ARMv5 faults unaligned word loads. With CONFIG_KASAN_VMALLOC and<br />
CONFIG_VMAP_STACK enabled, ARM926/VersatilePB crashes in __switch_to()<br />
with an alignment exception before reaching init.<br />
<br />
Use ldrb for the dummy shadow access. The code only needs to fault in the<br />
shadow mapping if the stack shadow is missing, so a byte load is sufficient<br />
and matches the granularity of KASAN shadow memory.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.1.120 (including) | 6.1.176 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.6.64 (including) | 6.6.143 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.12.4 (including) | 6.12.94 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.36 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.13 (excluding) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/2a4dc9a0ac3326e79fb58fdaae724b92127709a9
- https://git.kernel.org/stable/c/517720913bd3c17a52cd55a740064f68455ab88e
- https://git.kernel.org/stable/c/77a1f6883dc6e837bb2cb30b9b02e2f94338e2c6
- https://git.kernel.org/stable/c/c0b8c148a7754826156993ed6442d31536ec86b4
- https://git.kernel.org/stable/c/c2e3aadc8fef7da068490597fc5582f8f362aeb2
- https://git.kernel.org/stable/c/c74990828d3c486ee44aaa68240eb3abff289d1c



