CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-53154

mediumCVSS 5.5covered by 4 sourcesfirst seen 2026-06-09
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (CVE-2025-54518) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 platform drivers; - ARM64 architecture; - Cryptographic API; - PSP security protocol; - User-space API (UAPI); - Kernel build system; - ARM32 architecture; - MIPS architecture; - PowerPC architecture; - RISC-V architecture; - S390 architecture; - User-Mode Linux (UML); - x86 architecture; - Block layer subsystem; - Compute Acceleration Framework; - Intel NPU Driver; - ACPI drivers; - Android drivers; - Auxiliary display drivers; - Drivers core; - DRBD Distributed Replicated Block Device drivers; - Rados block device (RBD) driver; - Ublk userspace block driver; - Compressed RAM block device driver; - Bluetooth drivers; - Bus devices; - Character device driver; - Hardware random number generator core; - Clock framework and drivers; - CPU frequency scaling framework; - Hardware crypto device drivers; - Buffer Sharing and Synchronization framework; - DPLL subsystem; - EDAC drivers; - Arm Firmware Framework for ARMv8-A(FFA); - EFI core; - Intel Stratix 10 firmware drivers; - FPGA Framework; - FWCTL subsystem; - GPIO subsystem; - GPU drivers; - HID subsystem; - Hardware monitoring drivers; - CoreSight HW tracing drivers; - I2C subsystem; - I3C su

CSIRTS triage

Other
What
The vulnerability involves restoring reservation on error in hugetlb folio copy paths.
Who is affected
Deployments using hugetlb memory management.
Urgency
Remediation is medium urgency due to the medium severity rating.
Action
Apply the patch to address the error handling in hugetlb.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-53154

Get an email if CVE-2026-53154 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (4)

External references

NVD record for CVE-2026-53154

CVE.org record

Embed the live status

CVE-2026-53154 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-53154 status](https://www.csirts.com/badge/CVE-2026-53154)](https://www.csirts.com/cve/CVE-2026-53154)