Review reviewHigh

CVE-2026-53057

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: iommu/riscv: Add IOTINVAL after updating DDT/PDT entries Add riscv_iommu_iodir_iotinval() to perform required TLB and context cache invalidations after updating DDT or PDT entries, as mandated by the RISC-V IOMMU specification (Section 6.3.1 and 6.3.2).

CVSS
8.8
EPSS
0.13%
2.76% percentile
CISA KEV
Not listed
Published
2026.06.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.13%
Technical severityCVSS 8.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: iommu/riscv: Add IOTINVAL after updating DDT/PDT entries Add riscv_iommu_iodir_iotinval() to perform required TLB and context cache invalidations after updating DDT or PDT entries, as mandated by the RISC-V IOMMU specification (Section 6.3.1 and 6.3.2).

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 488ffbf181718b9ad8c1838cb249d60973e78eda < 3f917d9bff68600f77561900f3145bd4706dc840, >= 488ffbf181718b9ad8c1838cb249d60973e78eda < d99d1c13faa793ff1abab0d20ab6473c838081b3, >= 488ffbf181718b9ad8c1838cb249d60973e78eda < f5c262b544975e067ea265fc7403aefbbea8563e, >= 6.13, >= 6.13 < 6.18.33, >= 6.19 < 7.0.10
Fixed versions
6.18.33, 7.0.10

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE
Not available