CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-53075

criticalCVSS 9.8covered by 30 sourcesfirst seen 2026-06-09
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive information (kernel memory). (CVE-2023-45896) It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (CVE-2025-54518) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - MIPS architecture; - PowerPC architecture; - S390 architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - ACPI drivers; - ATM drivers; - Drivers core; - Power management core; - DRBD Distributed Replicated Block Device drivers; - RNBD block device driver; - Bluetooth drivers; - Bus devices; - Character device driver; - TPM device driver; - Clocksource drivers; - Data acquisition framework and drivers; - CPU frequency scaling framework; - CPU idle management framework; - Hardware crypto device drivers; - DMA engine subsystem; - Arm Firmware Framework for ARMv8-A(FFA); - EFI core; - GPIO subsystem; - GPU drivers; - HID subsystem; - Hardware monitoring drivers; - I2C subsystem; - IIO subsystem; - IIO ADC drivers; - InfiniBand drivers; - Input Device (Miscellaneous) drivers; - IOMMU subsystem; - Mailbox framework; - Multiple devices driver; - Media drivers; - MediaTek SMI driver; - NVIDIA Te

CSIRTS triage

What
Multiple vulnerabilities including NTFS file name length validation bypass, AMD floating point divider data exposure, and AMD Zen 2 operation cache isolation issues.
Who is affected
Systems using Intel IoTG kernel variants with NTFS, and AMD processor-based systems are affected by their respective vulnerabilities.
Urgency
High urgency; these include local privilege escalation on Zen 2 processors and kernel memory disclosure through NTFS exploitation.
Action
Apply Linux kernel USN-8620-4 security update for Intel IoTG variant or equivalent patches from your distribution.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-53075

Get an email if CVE-2026-53075 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (30)

External references

NVD record for CVE-2026-53075

CVE.org record

Embed the live status

CVE-2026-53075 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-53075 status](https://www.csirts.com/badge/CVE-2026-53075)](https://www.csirts.com/cve/CVE-2026-53075)