PT-2026-52295 · Linux · Linux Kernel

CVE-2026-53199

·

Published

2026-06-09

·

Updated

2026-09-07

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the netvsc copy to send buf() function where page buffer entries are copied into the VMBus send buffer using phys to virt() on the entry PFN. On 32-bit x86 systems with CONFIG HIGHMEM=y, entries for skb fragments referencing page cache or user pages may reside above the LOWMEM boundary. In such cases, phys to virt() returns an address outside the direct map, causing a fatal memcpy() fault on the transmit softirq path.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-90767
BDU:2026-14033
CVE-2026-53199
ECHO-13FC-89E5-6A1B
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel