Bug 2492310 (CVE-2026-53053)
| Summary: | CVE-2026-53053 kernel: iommu/amd: Fix clone_alias() to use the original device's devid | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the Linux kernel's IOMMU (Input/Output Memory Management Unit) AMD driver. The `clone_alias()` function incorrectly uses the device ID (devid) when handling alias devices. This can lead to the propagation of wrong or stale Device Table Entry (DTE) entries to alias devices, potentially impacting system stability or data integrity.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-06-24 18:04:56 UTC
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2026062400-CVE-2026-53053-5305@gregkh/T This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:61887 https://access.redhat.com/errata/RHSA-2026:61887 |