<?xml version="1.0" encoding="UTF-8"?>
<VrdaData refvuldefversion="1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://vrda.jpcert.or.jp" xsi:schemaLocation="http://vrda.jpcert.or.jp/feed/xsd/vrda_data.xsd">
  <VrdaDataProvider>
    <Name>JVN iPedia</Name>
    <URL>http://jvndb.jvn.jp</URL>
  </VrdaDataProvider>
  <VrdaDataSourceType>Advisory</VrdaDataSourceType>
  <Vulinfo revisionno="1" lang="ja" invalidated="false">
    <VulinfoID>JVNDB-2026-024878</VulinfoID>
    <VulinfoData>
      <Title>Linux&#12398;Linux Kernel&#12395;&#12362;&#12369;&#12427;&#35299;&#25918;&#28168;&#12415;&#12513;&#12514;&#12522;&#12398;&#20351;&#29992;&#12395;&#38306;&#12377;&#12427;&#33030;&#24369;&#24615;</Title>
      <VulinfoDescription>
        <Overview>Linux&#12459;&#12540;&#12493;&#12523;&#12395;&#12362;&#12356;&#12390;&#12289;&#20197;&#19979;&#12398;&#33030;&#24369;&#24615;&#12364;&#20462;&#27491;&#12373;&#12428;&#12414;&#12375;&#12383;&#12290;KVM: x86&#12395;&#12362;&#12369;&#12427;&#20104;&#26399;&#12375;&#12394;&#12356;&#12525;&#12540;&#12523;&#12395;&#12424;&#12427;&#12471;&#12515;&#12489;&#12540;&#12506;&#12540;&#12472;&#12531;&#12464;&#12398;Use-After-Free&#12398;&#21839;&#38988;&#12391;&#12377;&#12290;&#12467;&#12511;&#12483;&#12488;0cb2af2ea66ad&#65288;&#12300;KVM: x86: Fix shadow paging use-after-free due to unexpected GFN&#12301;&#65289;&#12391;&#12399;&#12289;&#20445;&#23384;&#12373;&#12428;&#12390;&#12356;&#12427;GFN&#12392;&#35336;&#31639;&#12373;&#12428;&#12383;GFN&#12364;&#19968;&#33268;&#12375;&#12394;&#12356;&#12371;&#12392;&#12395;&#36215;&#22240;&#12377;&#12427;&#12471;&#12515;&#12489;&#12540;&#12506;&#12540;&#12472;&#12531;&#12464;&#12398;&#21839;&#38988;&#12434;&#20462;&#27491;&#12375;&#12414;&#12375;&#12383;&#12290;&#12371;&#12398;&#12496;&#12464;&#12399;&#12289;&#12466;&#12473;&#12488;&#22806;&#37096;&#12363;&#12425;PDE&#12510;&#12483;&#12500;&#12531;&#12464;&#12434;&#22793;&#26356;&#12375;&#12289;&#12381;&#12398;&#24460;memslot&#12434;&#21066;&#38500;&#12377;&#12427;&#12371;&#12392;&#12391;&#12488;&#12522;&#12460;&#12540;&#12373;&#12428;&#12427;&#21487;&#33021;&#24615;&#12364;&#12354;&#12426;&#12414;&#12375;&#12383;&#12290;rmap_remove()&#12398;&#21628;&#12403;&#20986;&#12375;&#12399;&#12289;PDE&#22793;&#26356;&#24460;&#12395;&#20316;&#25104;&#12373;&#12428;&#12383;&#12456;&#12531;&#12488;&#12522;&#12434;&#35211;&#36867;&#12375;&#12390;&#12375;&#12414;&#12356;&#12414;&#12377;&#12290;&#12394;&#12380;&#12394;&#12425;&#12289;&#12522;&#12540;&#12501;SPTE&#12398;GFN&#12364;struct kvm_mmu_page&#12398;GFN&#12392;&#19968;&#33268;&#12375;&#12394;&#12356;&#12363;&#12425;&#12391;&#12377;&#12290;&#12375;&#12363;&#12375;&#12289;&#20462;&#27491;&#12373;&#12428;&#12383;&#12496;&#12464;&#12392;&#20284;&#12383;&#33030;&#24369;&#24615;&#12364;&#12289;&#22793;&#26356;&#12373;&#12428;&#12383;PDE&#12364;&#38750;&#12522;&#12540;&#12501;&#12506;&#12540;&#12472;&#12434;&#25351;&#12375;&#12390;&#12356;&#12427;&#22580;&#21512;&#12395;&#12399;&#20381;&#28982;&#12392;&#12375;&#12390;&#27531;&#12387;&#12390;&#12356;&#12414;&#12377;&#12290;&#12371;&#12398;&#22580;&#21512;&#12289;GFN&#12399;&#19968;&#33268;&#12373;&#12379;&#12427;&#12371;&#12392;&#12364;&#12391;&#12365;&#12414;&#12377;&#12364;&#12289;&#12525;&#12540;&#12523;&#12399;&#19968;&#33268;&#12375;&#12414;&#12379;&#12435;&#12290;&#20803;&#12398;&#22823;&#12365;&#12394;2MB&#12506;&#12540;&#12472;&#12399;direct=1&#12398;kvm_mmu_page&#12434;&#29983;&#25104;&#12375;&#12414;&#12377;&#12364;&#12289;&#26032;&#12375;&#12356;4KB&#12506;&#12540;&#12472;&#12399;direct=0&#12398;kvm_mmu_page&#12434;&#24517;&#35201;&#12392;&#12375;&#12414;&#12377;&#12290;&#12375;&#12363;&#12375;&#12289;kvm_mmu_get_child_sp()&#12399;&#12525;&#12540;&#12523;&#12434;&#27604;&#36611;&#12375;&#12394;&#12356;&#12383;&#12417;&#12289;&#12381;&#12398;&#12506;&#12540;&#12472;&#12434;&#20877;&#21033;&#29992;&#12375;&#12390;&#12375;&#12414;&#12356;&#12414;&#12377;&#12290;&#27425;&#12398;&#12473;&#12486;&#12483;&#12503;&#12392;&#12375;&#12390;&#12289;&#26032;&#12375;&#12356;&#12497;&#12473;&#19978;&#12395;&#12522;&#12540;&#12501;&#65288;4KB&#65289;SPTE&#12434;&#12452;&#12531;&#12473;&#12488;&#12540;&#12523;&#12375;&#12414;&#12377;&#12290;&#12371;&#12428;&#12399;walk&#12395;&#12424;&#12387;&#12390;&#35299;&#27770;&#12373;&#12428;&#12383;GFN&#12398;&#19979;&#12395;rmap&#12456;&#12531;&#12488;&#12522;&#12434;&#35352;&#37682;&#12375;&#12414;&#12377;&#12290;&#12375;&#12363;&#12375;&#12289;&#12381;&#12398;&#23376;&#12364;&#25273;&#28040;&#12373;&#12428;&#12427;&#12392;&#12289;&#12381;&#12398;&#35242;&#12391;&#12354;&#12427;kvm_mmu_page&#12399;direct=1&#12434;&#25345;&#12385;&#12289;kvm_mmu_page_get_gfn()&#12399;sp-&#65310;shadowed_translation[]&#65288;&#12414;&#12383;&#12399;&#21476;&#12356;&#12459;&#12540;&#12493;&#12523;&#12391;&#12399;sp-&#65310;gfns[]&#65289;&#12434;&#20351;&#29992;&#12379;&#12378;&#12395;4KB&#12506;&#12540;&#12472;&#12398;GFN&#12434;sp-&#65310;gfn + index&#12392;&#12375;&#12390;&#35336;&#31639;&#12375;&#12414;&#12377;&#12290;&#12381;&#12398;&#12383;&#12417;&#12289;&#35352;&#37682;&#12373;&#12428;&#12383;&#12456;&#12531;&#12488;&#12522;&#12434;&#21066;&#38500;&#12391;&#12365;&#12414;&#12379;&#12435;&#12290;memslot&#12364;&#21066;&#38500;&#12373;&#12428;&#12427;&#12392;&#12289;&#12471;&#12515;&#12489;&#12540;&#12506;&#12540;&#12472;&#12399;&#35299;&#25918;&#12373;&#12428;&#12414;&#12377;&#12364;&#12289;rmap&#12456;&#12531;&#12488;&#12522;&#12399;&#27531;&#23384;&#12375;&#12414;&#12377;&#12290;&#12371;&#12428;&#12399;&#12377;&#12391;&#12395;&#20462;&#27491;&#12373;&#12428;&#12383;&#12471;&#12490;&#12522;&#12458;&#12392;&#21516;&#27096;&#12391;&#12377;&#12290;&#12381;&#12398;&#24460;&#12289;&#12381;&#12398;GFN&#12434;&#36799;&#12427;&#12467;&#12540;&#12489;&#65288;&#12480;&#12540;&#12486;&#12451;&#12525;&#12464;&#35352;&#37682;&#12289;MMU&#12494;&#12540;&#12486;&#12451;&#12501;&#12449;&#12452;&#12450;&#12398;&#28961;&#21177;&#21270;&#12394;&#12393;&#65289;&#12399;&#12289;&#35299;&#25918;&#28168;&#12415;&#12398;&#12506;&#12540;&#12472;&#20869;&#12395;&#12354;&#12427;sptep&#12434;&#21442;&#29031;&#12375;&#12289;Use-After-Free&#12434;&#24341;&#12365;&#36215;&#12371;&#12375;&#12414;&#12377;&#12290;</Overview>
      </VulinfoDescription>
      <Affected>
        <AffectedItem affectedstatus="vulnerable">
          <Lapt>cpe:/o:linux:linux_kernel</Lapt>
        </AffectedItem>
      </Affected>
      <FactAnalysis>
      </FactAnalysis>
      <Related>
        <RelatedItem relationtype="self" origin="jvnipedia">
          <URL>https://jvndb.jvn.jp/ja/contents/2026/JVNDB-2026-024878.html</URL>
        </RelatedItem>
        <RelatedItem relationtype="alternate" origin="other">
          <Name>Common Vulnerabilities and Exposures (CVE)</Name>
          <VulinfoID>CVE-2026-53359</VulinfoID>
          <URL>https://www.cve.org/CVERecord?id=CVE-2026-53359</URL>
        </RelatedItem>
        <RelatedItem relationtype="alternate" origin="other">
          <Name>National Vulnerability Database (NVD)</Name>
          <VulinfoID>CVE-2026-53359</VulinfoID>
          <URL>https://nvd.nist.gov/vuln/detail/CVE-2026-53359</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>JVNDB</Name>
          <VulinfoID>CWE-416</VulinfoID>
          <Title>&#35299;&#25918;&#28168;&#12415;&#12513;&#12514;&#12522;&#12398;&#20351;&#29992;</Title>
          <URL>https://cwe.mitre.org/data/definitions/416.html</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>&#38306;&#36899;&#25991;&#26360;</Name>
          <VulinfoID>KVM: x86: Fix shadow paging use-after-free due to unexpected role - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/2ad3afa40ac6aa340dada122f9abfa46c0a6eb35)</VulinfoID>
          <URL>https://git.kernel.org/stable/c/2ad3afa40ac6aa340dada122f9abfa46c0a6eb35</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>&#38306;&#36899;&#25991;&#26360;</Name>
          <VulinfoID>KVM: x86: Fix shadow paging use-after-free due to unexpected role - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/9291654d69e08542de37755cebe4d5b02c3170d1)</VulinfoID>
          <URL>https://git.kernel.org/stable/c/9291654d69e08542de37755cebe4d5b02c3170d1</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>&#38306;&#36899;&#25991;&#26360;</Name>
          <VulinfoID>KVM: x86: Fix shadow paging use-after-free due to unexpected role - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/5e470998a23e4c3d89ed24e8172cb22747e61efa)</VulinfoID>
          <URL>https://git.kernel.org/stable/c/5e470998a23e4c3d89ed24e8172cb22747e61efa</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>&#38306;&#36899;&#25991;&#26360;</Name>
          <VulinfoID>KVM: x86: Fix shadow paging use-after-free due to unexpected role - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/81ccda30b4e83d8f5cc4fd50503c44e3a33abfeb)</VulinfoID>
          <URL>https://git.kernel.org/stable/c/81ccda30b4e83d8f5cc4fd50503c44e3a33abfeb</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>&#38306;&#36899;&#25991;&#26360;</Name>
          <VulinfoID>KVM: x86: Fix shadow paging use-after-free due to unexpected role - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/1ae7d5a6db6c190ce183e3098ca0e0846e14d462)</VulinfoID>
          <URL>https://git.kernel.org/stable/c/1ae7d5a6db6c190ce183e3098ca0e0846e14d462</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>&#38306;&#36899;&#25991;&#26360;</Name>
          <VulinfoID>KVM: x86: Fix shadow paging use-after-free due to unexpected role - kernel/git/stable/linux.git - Linux kernel stable tree (https://git.kernel.org/stable/c/b1337aae5e194324e4810d561764e7793f8b3864)</VulinfoID>
          <URL>https://git.kernel.org/stable/c/b1337aae5e194324e4810d561764e7793f8b3864</URL>
        </RelatedItem>
        <RelatedItem relationtype="reference" origin="other">
          <Name>&#38306;&#36899;&#25991;&#26360;</Name>
          <VulinfoID>oss-security - Januscape: Guest-to-Host Escape in KVM/x86 (CVE-2026-53359)</VulinfoID>
          <URL>http://www.openwall.com/lists/oss-security/2026/07/06/7</URL>
        </RelatedItem>
      </Related>
      <DateFirstPublished>2026-07-24T10:04:26+09:00</DateFirstPublished>
      <DateLastUpdated>2026-07-24T10:04:26+09:00</DateLastUpdated>
    </VulinfoData>
  </Vulinfo>
</VrdaData>
