{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-53159","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-06-09T07:44:35.388Z","datePublished":"2026-06-25T08:38:41.482Z","dateUpdated":"2026-08-05T12:33:33.871Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:33:33.871Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: fix DMA address corruption due to find_vma misuse\n\nfastrpc_get_args() uses find_vma() to look up the VMA for a user-provided\npointer and compute a DMA address offset. When the address falls in a gap\nbefore the returned VMA, (ptr & PAGE_MASK) - vma->vm_start underflows,\ncorrupting the DMA address sent to the DSP.\n\nReplace find_vma() with vma_lookup(), which returns NULL when the address\nis not contained within any VMA."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable code is reached through local FastRPC misc-device ioctls, especially FASTRPC_IOCTL_INVOKE, not through network packets or adjacent/physical input.\nAC:L - The attacker controls the invoke arguments, DMA-buf fd, length, and user address layout; placing the pointer in a VMA gap is straightforward with mmap/munmap and no race is required.\nPR:L - A caller needs local access to an openable /dev/fastrpc-* device, but the kernel path has no capable() check and FastRPC supports untrusted/unsigned user protection domains on relevant Qualcomm DSP deployments.\nUI:N - The attacker triggers the ioctl path directly and does not need another user to open files, mount anything, or perform an action.\nS:C - The corrupted address is consumed across the host/DSP DMA/IOMMU boundary, so the bug can affect memory resources outside the caller’s intended FastRPC buffer authority.\nC:H - The underflow can make an attacker-controlled DSP invocation read from unintended DMA/IOMMU-visible memory rather than the supplied buffer, which is a plausible high-impact information disclosure primitive.\nI:H - For output or bidirectional buffers, the same corrupted DMA address can direct DSP writes to unintended DMA/IOMMU-visible memory, giving a plausible high-impact memory corruption primitive.\nA:H - Invalid or unintended DMA addresses can trigger IOMMU/DSP faults, hangs, or kernel-facing subsystem failure, producing high availability impact."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/misc/fastrpc.c"],"versions":[{"version":"80f3afd72bd4149c57daf852905476b43bb47647","lessThan":"d43afc412d439ffca1567e7ca8652be22f272b3b","status":"affected","versionType":"git"},{"version":"80f3afd72bd4149c57daf852905476b43bb47647","lessThan":"2d0f47e27c1fa718b29c69aa7c96a2c5161bc2c2","status":"affected","versionType":"git"},{"version":"80f3afd72bd4149c57daf852905476b43bb47647","lessThan":"708c17b52c60fe7a57e73b495bdee50f58feb48c","status":"affected","versionType":"git"},{"version":"80f3afd72bd4149c57daf852905476b43bb47647","lessThan":"d3e26df2e8eb361e6bef096b2fd565476a1f14c4","status":"affected","versionType":"git"},{"version":"80f3afd72bd4149c57daf852905476b43bb47647","lessThan":"e69e306a4cccb40a73511350cb280825a556ce3c","status":"affected","versionType":"git"},{"version":"80f3afd72bd4149c57daf852905476b43bb47647","lessThan":"53e06f8a3c2b085c31bf1284e2ebcb8036e99625","status":"affected","versionType":"git"},{"version":"80f3afd72bd4149c57daf852905476b43bb47647","lessThan":"7ba7b30ddb04646d4d638f4d8c4718a304bbbddd","status":"affected","versionType":"git"},{"version":"80f3afd72bd4149c57daf852905476b43bb47647","lessThan":"464c6ad2aa16e1e1df9d559289199356493d1e00","status":"affected","versionType":"git"},{"version":"954edc466128479872731d06f026d0e71840d153","status":"affected","versionType":"git"},{"version":"5.1.6","lessThan":"5.2","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/misc/fastrpc.c"],"versions":[{"version":"5.2","status":"affected"},{"version":"0","lessThan":"5.2","status":"unaffected","versionType":"semver"},{"version":"5.10.260","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.94","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.36","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.13","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"5.10.260"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"5.15.210"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.1.176"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.6.143"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.12.94"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.18.36"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"7.0.13"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"7.1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.1.6"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/d43afc412d439ffca1567e7ca8652be22f272b3b"},{"url":"https://git.kernel.org/stable/c/2d0f47e27c1fa718b29c69aa7c96a2c5161bc2c2"},{"url":"https://git.kernel.org/stable/c/708c17b52c60fe7a57e73b495bdee50f58feb48c"},{"url":"https://git.kernel.org/stable/c/d3e26df2e8eb361e6bef096b2fd565476a1f14c4"},{"url":"https://git.kernel.org/stable/c/e69e306a4cccb40a73511350cb280825a556ce3c"},{"url":"https://git.kernel.org/stable/c/53e06f8a3c2b085c31bf1284e2ebcb8036e99625"},{"url":"https://git.kernel.org/stable/c/7ba7b30ddb04646d4d638f4d8c4718a304bbbddd"},{"url":"https://git.kernel.org/stable/c/464c6ad2aa16e1e1df9d559289199356493d1e00"}],"title":"misc: fastrpc: fix DMA address corruption due to find_vma misuse","x_generator":{"engine":"bippy-1.2.0"}}}}