{"id":"CVE-2026-53322","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/pci: Clean up DMABUFs before disabling function\n\nOn device shutdown, make vfio_pci_core_close_device() call\nvfio_pci_dma_buf_cleanup() before the function is disab…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/pci: Clean up DMABUFs before disabling function\n\nOn device shutdown, make vfio_pci_core_close_device() call\nvfio_pci_dma_buf_cleanup() before the function is disab…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-415","CWE-826"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 6.19, < 7.0.10"],"patched":["linux_kernel 7.0.10"],"published":"2026-06-26","updated":"2026-09-09","sourceUpdated":"2026-09-09T13:20:29.680","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-53322","references":[{"url":"https://git.kernel.org/stable/c/4f1000a30f67cf7d328059242776a858611d5ef9","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d97708701434ce72968e771976aaf9d3438fcafd","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://access.redhat.com/errata/RHSA-2026:65334","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-53322","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2493709","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53322.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-14T11:12:35.837Z","epss":0.0013,"epssPercentile":0.0297,"slug":"CVE-2026-53322","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nvfio/pci: Clean up DMABUFs before disabling function\n\nOn device shutdown, make vfio_pci_core_close_device() call\nvfio_pci_dma_buf_cleanup() before the function is disabled via\nvfio_pci_core_disable().  This ensures that all access via DMABUFs is\nrevoked before the function's BARs become inaccessible.\n\nThis fixes an issue where, if the function is disabled first, a tiny\nwindow exists in which the function's MSE is cleared and yet BARs\ncould still be accessed via the DMABUF.  The resources would also be\nfreed and up for grabs by a different driver.\n\n## Affected\n\n- `linux_kernel >= 6.19, < 7.0.10`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 7.0.10`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}