---
id: CVE-2026-53372
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  iommu/vt-d: Block PASID attachment to nested domain with dirty tracking

  Kernel lacks dirty tracking support on nested domain attached to PASID,
  fails the attachment ea…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  iommu/vt-d: Block PASID attachment to nested domain with dirty tracking

  Kernel lacks dirty tracking support on nested domain attached to PASID,
  fails the attachment ea…
severity: none
published: '2026-07-19'
updated: '2026-07-19'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53372'
references:
  - url: 'https://git.kernel.org/stable/c/3ea9ce757bd3de955b56e7bc5672fc479e40b045'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9009c1af5458322469fa9a4371081a4449c5947d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/cc5bd898ff70710ffc41cd8e5c2741cb64750047'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00124
epssPercentile: 0.02453
ingestedAt: '2026-07-19T14:31:07.454Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

iommu/vt-d: Block PASID attachment to nested domain with dirty tracking

Kernel lacks dirty tracking support on nested domain attached to PASID,
fails the attachment early if nesting parent domain is dirty tracking
configured, otherwise dirty pages would be lost.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
