CVE-2026-53343 Details
Description
In the Linux kernel, the following vulnerability has been resolved: ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow Commit 44e9a3bb76e5 ("ARM: 9430/1: entry: Do a dummy read from VMAP shadow") added a dummy read from the KASAN VMAP stack shadow in __switch_to(). The read uses ldr, but the KASAN shadow address is byte-granular and is not guaranteed to be word aligned. ARMv5 faults unaligned word loads. With CONFIG_KASAN_VMALLOC and CONFIG_VMAP_STACK enabled, ARM926/VersatilePB crashes in __switch_to() with an alignment exception before reaching init. Use ldrb for the dummy shadow access. The code only needs to fault in the shadow mapping if the stack shadow is missing, so a byte load is sufficient and matches the granularity of KASAN shadow memory.
A vulnerability in the Linux kernel's handling of the KASAN VMAP stack shadow can lead to a crash on ARM926/VersatilePB systems. The issue arises because the KASAN shadow address is byte-granular and not guaranteed to be word-aligned. When the kernel attempts to read the shadow using a word load, it triggers an alignment exception, causing a crash. This vulnerability occurs with CONFIG_KASAN_VMALLOC and CONFIG_VMAP_STACK enabled.
The vulnerability has been addressed by modifying the kernel to use byte loads for the KASAN VMAP stack shadow, ensuring proper alignment. Users should upgrade to the patched version of the Linux kernel.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/2a4dc9a0ac3326e79fb58fdaae724b92127709a9 | kernel.org | Patch |
| https://git.kernel.org/stable/c/517720913bd3c17a52cd55a740064f68455ab88e | kernel.org | Patch |
| https://git.kernel.org/stable/c/77a1f6883dc6e837bb2cb30b9b02e2f94338e2c6 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c0b8c148a7754826156993ed6442d31536ec86b4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c2e3aadc8fef7da068490597fc5582f8f362aeb2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c74990828d3c486ee44aaa68240eb3abff289d1c | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.1.120, < 6.1.176 >= 6.6.64, < 6.6.143 >= 6.12.4, < 6.12.94 >= 6.13, < 6.18.36 >= 6.19, < 7.0.13 7.1 rc1 7.1 rc2 7.1 rc3 7.1 rc4 7.1 rc5 7.1 rc6 7.1 rc7 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | Initial Analysis | [email protected] |
| Jul 1, 2026 | New CVE Received | kernel.org |