CVE-2026-53360Disclosure(linux / linux_kernel)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use As per the GHCB spec, when using GHCB v2+ require the software scratch area to reside in the GHCB's shared buffer. Note, things like Page State Change (PSC) requests _rely_ on this behavior, as the guest can't provide a length when making the request, i.e. the size of the guest payload is bounded by the size of the shared buffer. Failure to force usage of the GHCB, and a slew of other flaws, lets a malicious SNP guest corrupt host kernel heap memory, and leak host heap layout information. setup_vmgexit_scratch() allocates a buffer via kvzalloc(exit_info_2), where exit_info_2 is guest-controlled. With exit_info_2=24, this yields a 24-byte allocation in kmalloc-cg-32 (32-byte slab objects). The buffer holds an 8-byte psc_hdr followed by 8-byte psc_entry structs, so only entries[0] and entries[1] are in-bounds. snp_begin_psc() validates end_entry against VMGEXIT_PSC_MAX_COUNT (253) but NOT against the actual buffer size: idx_end = hdr->end_entry; if (idx_end >= VMGEXIT_PSC_MAX_COUNT) { // checks 253, not buffer snp_complete_psc(svm, ...); return 1; } for (idx = idx_start; idx <= idx_end; idx++) { entry_start = entries[idx]; // OOB when idx >= 2 The guest sets end_entry=10+, causing the host to iterate entries[2+] which are OOB into adjacent slab objects. For each OOB entry: - The host reads 8 bytes (OOB READ / info leak oracle) - If the data passes PSC validation, __snp_complete_one_psc() writes cur_page = 1 or 512 into the entry (OOB WRITE, sev.c:3806) - If validation fails, the error response reveals whether adjacent memory is zero vs non-zero (information disclosure to guest) The guest controls allocation size (exit_info_2), entry range (cur_entry/end_entry), and can fire unlimited VMGEXITs to repeatedly hit different slab positions. By exploiting the variety of bugs, a malicious SEV-SNP guest can: - OOB read adjacent kmalloc-cg-32 objects (heap layout disclosure) - OOB write cur_page bits into adjacent objects (heap corruption) - Trigger use-after-free conditions across VMGEXITs E.g. with KASAN enabled, a single insmod of the PoC guest module produces 73 KASAN reports: BUG: KASAN: slab-out-of-bounds in snp_begin_psc+0x126/0x890 Read of size 8 at addr ffff888219ffb5e0 by task qemu-system-x86/2199 BUG: KASAN: slab-out-of-bounds in snp_begin_psc+0x468/0x890 Write of size 8 at addr ffff888351566648 by task qemu-system-x86/2199 The buggy address belongs to the object at ffff888XXXXXXXXX which belongs to the cache kmalloc-cg-32 of size 32 The buggy address is located N bytes to the right of allocated 32-byte region [ffff888XXXXXXXXX, ffff888XXXXXXXXX) Breakdown: 62 slab-out-of-bounds (reads + writes past allocation) 7 slab-use-after-free 4 use-after-free All credit to Stan for the wonderful description and reproducer! [sean: write changelog]

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-08-12); latest day: 1
  • 9 total mentions across 7 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline9 mentions / 7d
01223Mentions · 2026-07-05: 1Mentions · 2026-07-26: 1Mentions · 2026-08-11: 1Mentions · 2026-08-12: 3Mentions · 2026-08-20: 1Mentions · 2026-08-26: 1Mentions · 2026-09-29: 1PoC Mentioned / Linked · 2026-08-12: 1PoC Mentioned / Linked · 2026-08-26: 1Patch / Workaround · 2026-07-26: 1Patch / Workaround · 2026-08-12: 3Patch / Workaround · 2026-08-26: 1Technical Details · 2026-07-26: 1Technical Details · 2026-08-11: 1Technical Details · 2026-08-12: 3Technical Details · 2026-08-20: 107-0507-2608-1108-1208-2008-2609-29
Signal classification4 categories
Disclosure
337.5%
Patch
337.5%
General
112.5%
PoC
112.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-07-051
Disclosure1
2026-07-261
Patch1
2026-08-111
Disclosure1
2026-08-123
Disclosure1Patch2
2026-08-201
General1
2026-08-261
PoC1
Full discourse9 posts
  • 0xor0ne@0xor0ne
    General

    Analysis of CVE-2026-53360: heap out-of-bounds read/write in KVM’s SEV-SNP Page State Change handler (@anand_himanshu) https://blog.himanshuanand.com/2026/08/i-found-a-kvm-guest-to-host-heap-corruption-bug-and-someone-else-got-there-first/ #infosec https://t.co/ojL2EQYYNu

    Post summary

    The tweet points to an analysis of CVE-2026-53360, noting a heap out-of-bounds issue in KVM’s SEV-SNP handler, but provides no proof of concept, exploit code, patch, or evidence of active exploitation.

    4130117457.3K
    94.0K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2026-53360: KVM SEV-SNP guest-to-host heap OOB and analysis of the upstream fix https://blog.himanshuanand.com/2026/08/i-found-a-kvm-guest-to-host-heap-corruption-bug-and-someone-else-got-there-first/

    Post summary

    The post reports a newly discovered guest‑to‑host heap out‑of‑bounds bug in KVM SEV‑SNP and examines the upstream patch that addresses the issue.

    07025135.9K
    161.5K followersView on X
  • /r/netsec@_r_netsec

    CVE-2026-53360: KVM SEV-SNP guest-to-host heap OOB and analysis of the upstream fix https://blog.himanshuanand.com/2026/08/i-found-a-kvm-guest-to-host-heap-corruption-bug-and-someone-else-got-there-first/

    0901971.4K
    34.1K followersView on X
  • Himanshu Anand@anand_himanshu
    Disclosure

    I found a guest -&gt; host memory corruption bug in KVM. Then I emailed the kernel security team. Their response, basically: Someone found it before you and the problem is bigger than what you found. That second part hurt more. 🧵 CVE-2026-53360 https://blog.himanshuanand.com/2026/08/i-found-a-vm-escape-bug-in-kvm-and-someone-else-got-there-first/

    Post summary

    The post announces a guest‑to‑host memory corruption bug in KVM (CVE‑2026‑53360), noting a larger issue identified by others, but does not provide PoC, exploit details, or patch information.

    22017111.9K
    761 followersView on X
  • OS開発者@hacker_infra
    PoC

    PoCがあるのでRed hatに報告 PoCをゲスト側でビルドしてモジュールをロードする必要があるのでゲスト側でroot権限が必用だし 難易度は高いかな https://bugzilla.redhat.com/show_bug.cgi?id=2497032 緩和策 https://access.redhat.com/security/cve/cve-2026-53360

    Post summary

    PoC for CVE‑2026‑53360 exists and requires root privileges on the guest to load a module; remediation steps have been provided via a Red Hat security advisory.

    00071655
    2.9K followersView on X
  • /r/netsec@_r_netsec
    Patch

    CVE-2026-53360: KVM SEV-SNP guest-to-host heap OOB and analysis of the upstream fix https://blog.himanshuanand.com/2026/08/i-found-a-kvm-guest-to-host-heap-corruption-bug-and-someone-else-got-there-first/

    Post summary

    The author reports a heap out-of-bounds bug (CVE-2026-53360) in KVM SEV-SNP and discusses the upstream patch that addresses the issue.

    030201.2K
    33.8K followersView on X
  • ✪ 𝕱𝖆𝖍𝖆𝖉@fad_777
    Patch

    ثغرة guest-to-host في KVM SEV-SNP تذكير مهم بأن العزل في الحوسبة السرية يعتمد على تفاصيل دقيقة داخل النواة. CVE-2026-53360 تتعلق بوصول خارج حدود الذاكرة على heap ضمن سياق KVM وSEV-SNP، مع تحليل للتصحيح المدمج upstream. أهمية هذا النوع من التحليل أنه لا يكتفي بوصف الثغرة، بل يساعد على فهم حدود الثقة بين الضيف والمضيف وكيفية معالجة الأخطاء في مسارات حساسة. القيمة العملية واضحة للمهتمين بأمن Linux Kernel، الافتراضية، وConfidential Computing: قراءة التصحيحات upstream تكشف كيف يتم تقليل سطح الهجوم بدون الاعتماد على الافتراضات النظرية فقط. A guest-to-host heap OOB in KVM SEV-SNP is exactly the kind of issue that deserves close attention in confidential computing. CVE-2026-53360 focuses on a memory-safety flaw across the VM isolation boundary, along with an analysis of the upstream fix. This matters because SEV-SNP is designed to strengthen guest protection, but the hypervisor and kernel paths handling that boundary still need rigorous validation. For kernel security, virtualization, and cloud infrastructure teams, the useful part is the upstream patch analysis: it shows how a real vulnerability is corrected at the source level and what reviewers should watch for in similar code paths. https://blog.himanshuanand.com/2026/08/i-found-a-kvm-guest-to-host-heap-corruption-bug-and-someone-else-got-there-first/ #KVM #SEVSNP #LinuxKernelSecurity

    Post summary

    A technical review of CVE‑2026‑53360, detailing a guest‑to‑host heap out‑of‑bounds flaw in KVM SEV‑SNP and the upstream patch that mitigates it.

    0000057
    85 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-53360 (CVSS 8.8) Linux kernel KVM SEV vulnerability allows malicious SEV-SNP guests to corrupt host heap memory &amp; leak layout info via OOB read/write in GHCB scratch area. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/Cf0Mb5nCs3

    Post summary

    The tweet announces CVE‑2026‑53360, details a KVM SEV out‑of‑bounds memory corruption that can expose host heap info, and urges immediate patching to mitigate the risk.

    0000055
    96 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Linux Kernel (CVE-2026-53360) https://vuldb.com/vuln/376322

    Post summary

    A new Linux Kernel vulnerability (CVE‑2026‑53360) with increased severity has been disclosed, with details linked to a public vulnerability database.

    00000162
    2.3K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--
OSlinuxlinux_kernel7.1--

Explore more