Correction, September 17, 2026: The previous GhostLock label, 97% success rate, and claim that arbitrary Linux users could almost certainly obtain root were not substantiated by the cited primary material and are withdrawn. CVE-2026-53359 concerns a use-after-free in x86 KVM shadow paging. It must not be confused with the separate rtmutex vulnerability.
Affected component and prerequisites
KVM provides virtual-machine execution on Linux. A shadow page can be reused without checking that its role matches the new mapping. A reverse-mapping entry then survives page removal, allowing later operations to dereference freed memory. Possible consequences include host-kernel memory corruption and a host crash.
The Linux CNA's scenario requires guest-code execution or access to KVM execution interfaces on an affected x86 host with the relevant shadow-paging configuration. The flaw is not directly reached through network packets. The assessment includes a guest-to-host boundary crossing; it does not establish identical exposure for every Linux desktop or container.
The displayed CVSS v3.1 score is the Linux CNA assessment, not an exploitation success rate. A proof-of-concept assessment also does not establish observed attacks or a real-world victim count.
Check the applicable fix
The CVE record identifies upstream fixes in 6.1.177, 6.6.144, 6.12.95, 6.18.38, 7.1.3, and 7.2 for their respective branches. Distribution packages may backport fixes while retaining older version numbers. Check the package vendor's CVE status instead of comparing upstream numbers alone.
- ✓Check the KVM host kernel and vendor advisory, not only the guest operating system
- ✓Install a vendor-confirmed fixed kernel and complete the required reboot or supported live-patching process
- ✓Verify the running kernel matches the intended fixed package
- ✓Restrict untrusted KVM workloads while updating and investigate abnormal host crashes
