Skip to content
major vulnerability· requires attention

Kernel-level IOMMU/page-table bug in Linux affects many distributions and platforms; can enable DMA/guest access to kernel memory — broad impact warranting org-wide notice.

Systems

CVE-2026-97525

8.2
High
EPSS n/aPatch availableSep 26, 2026

Linux kernel split page tables can leave stale IOTLB entries enabling DMA access to kernel memory.

common questions

Is CVE-2026-97525 being exploited?

Not confirmed. CVE-2026-97525 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked.

How severe is CVE-2026-97525?

CVE-2026-97525 is rated High with a CVSS score of 8.2. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.

Is there a patch for CVE-2026-97525?

Yes. A fix has been recorded for CVE-2026-97525. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.

What does CVE-2026-97525 affect?

CVE-2026-97525 affects Linux kernel (x86 mm/pat), Kernel versions prior to stable fixes in referenced commits. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.

What should I do about CVE-2026-97525?

Apply upstream kernel fixes or vendor-updates immediately; reboot if required.

Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.

executive summary
technical analysis
affected
Linux kernel (x86 mm/pat)Kernel versions prior to stable fixes in referenced commits
impact

Stale IOTLB entries may allow DMA-capable devices or malicious guests to read/modify kernel memory, causing data disclosure or privilege escalation.

action required

Patch when possible

affected versions
Linux Linux
  • affected>= b3039c526f3e1744db0cbb7ae1f0213f5e27d3f4 and < 84e0cd79d57f06b872154eb5d8f610584133f260
  • affected>= 5ba2f0a1556479638ac11a3c201421f5515e89f5 and < 922873cf4fc34124215070a8ad391bf831538bb9
  • affected>= 5ba2f0a1556479638ac11a3c201421f5515e89f5 and < 9e4a3ec3411bb6bb59e3c1f29b75609f1e87aac4
  • affected>= 6.18.7 and < 6.18.53
  • affected6.19
vendor says fixed in< 6.19, >= 6.18.53 and <= 6.18.*, >= 7.2.7 and <= 7.2.*, >= 7.3-rc4 and <= *

As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.

how to fix
Remediation steps are tailored for users whose stack is affected. Add this technology to your stack to see the fix checklist.
references
get alerted

Track only the vulnerabilities that affect your infrastructure.

start for free