Description
In the Linux kernel, the following vulnerability has been resolved:

iommu/vt-d: Block PASID attachment to nested domain with dirty tracking

Kernel lacks dirty tracking support on nested domain attached to PASID,
fails the attachment early if nesting parent domain is dirty tracking
configured, otherwise dirty pages would be lost.
Published: 2026-07-19
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel contains a defect in the IOMMU/VT‑d subsystem that prevents proper handling of PASID attachment for a nested domain when dirty tracking is enabled. The kernel prematurely rejects the attachment, leaving any dirty pages in the nested domain unwiped, which can result in lost or corrupted data during device passthrough operations. This flaw does not provide remote code execution or privilege escalation but does compromise data integrity for virtualized workloads that rely on nested IOMMU domains.

Affected Systems

The issue is present in all Linux kernels that expose the IOMMU/VT‑d subsystem for PASID attachment in nested virtualization setups. No specific version range is given in the advisory, so any affected kernel build that does not yet incorporate the patch should be considered at risk. The affected product is the Linux kernel itself.

Risk and Exploitability

With a CVSS score of 5.5 and an EPSS score of less than 1%, the vulnerability presents a moderate risk rating and is unlikely to see widespread exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would require a system that is both running a vulnerable kernel and utilizing nested IOMMU domains with dirty tracking. Since the defect triggers a kernel error and blocks attachment, the attack surface is limited to privileged operations that manage device assignments; it therefore does not enable arbitrary code execution or compromise beyond data loss. The likely attack vector is inferred to be internal privileged interactions with the IOMMU subsystem, as the flaw manifests during the PASID attachment process.

Generated by OpenCVE AI on July 30, 2026 at 22:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that has incorporated the patch for CVE‑2026‑53372
  • If the patch cannot be applied immediately, reconfigure virtualized workloads to disable dirty tracking for nested IOMMU domains or avoid attaching PASIDs to nested domains until the fix is available
  • Monitor kernel logs (dmesg, /var/log/kern.log) for IOMMU attachment failures and verify that nested domain usage complies with the updated policy

Generated by OpenCVE AI on July 30, 2026 at 22:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8593-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8603-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8618-1 Linux kernel vulnerabilities
History

Tue, 21 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-820
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sun, 19 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Block PASID attachment to nested domain with dirty tracking Kernel lacks dirty tracking support on nested domain attached to PASID, fails the attachment early if nesting parent domain is dirty tracking configured, otherwise dirty pages would be lost.
Title iommu/vt-d: Block PASID attachment to nested domain with dirty tracking
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-07-19T09:10:32.453Z

Reserved: 2026-06-09T07:44:35.401Z

Link: CVE-2026-53372

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-19T00:00:00Z

Links: CVE-2026-53372 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T22:45:04Z

Weaknesses