Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3444 articles · 168093 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-53120EXPLOITEDPATCHED
linux · linux kernel

PCI: use generic driver_override infrastructure

Description

A vulnerability, classified as critical, was found in Linux Kernel up to 6.12.90/6.18.32/7.0.9. Impacted is the function __driver_attach of the component PCI. Such manipulation of the argument driver_override leads to use after free. This vulnerability is documented as CVE-2026-53120. The attack requires being on the local network.

Affected Products

VendorProductVersions
linuxlinux kernel782a985d7af26db39e86070d28f987cad21313c0, 782a985d7af26db39e86070d28f987cad21313c0, 782a985d7af26db39e86070d28f987cad21313c0, 782a985d7af26db39e86070d28f987cad21313c0, 3.16, 6.12.90, 6.18.32, 7.0.9

References

  • https://git.kernel.org/stable/c/dfe950d9464cad609f3b118c6203e2708055bc61
  • https://git.kernel.org/stable/c/58a42be0d70307d765594fc581f5f5e5ef059712
  • https://git.kernel.org/stable/c/c5b2c5755495507e14f310c2653c85de0a309b1f
  • https://git.kernel.org/stable/c/10a4206a24013be4d558d476010cbf2eb4c9fa64

Related News (3 articles)

Tier A
Microsoft MSRC2h ago
CVE-2026-53120 PCI: use generic driver_override infrastructure
→ No new info (linked only)
Tier C
VulDB3d ago
CVE-2026-53120 | Linux Kernel up to 6.12.90/6.18.32/7.0.9 PCI __driver_attach driver_override use after free
→ No new info (linked only)
Tier C
Linux Kernel CVEs3d ago
CVE-2026-53120: PCI: use generic driver_override infrastructure
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
dfe950d9464cad609f3b118c6203e2708055bc6158a42be0d70307d765594fc581f5f5e5ef059712c5b2c5755495507e14f310c2653c85de0a309b1f10a4206a24013be4d558d476010cbf2eb4c9fa6406.12.916.18.337.0.107.1
PublishedJun 24, 2026
Last enriched3d agov2
Trending Score65
Source articles3
Independent3
Info Completeness7/14
Missing: cvss, epss, cwe, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-31431EXPKEV
crypto: algif_aead - Revert to operating out-of-place
Trending: 111
HIGHCVE-2026-43284EXPKEV
xfrm: esp: avoid in-place decrypt on shared skb frags
Trending: 106
HIGHCVE-2026-43500EXPKEV
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
Trending: 100
HIGHCVE-2026-46243EXP
smb: client: reject userspace cifs.spnego descriptions
Trending: 86
HIGHCVE-2026-46333EXP
ptrace: slightly saner 'get_dumpable()' logic
Trending: 70

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 24, 2026
Actively Exploited
Jun 24, 2026
Patch Available
Jun 24, 2026
Discovered by ZDM
Jun 24, 2026
Updated: description, severity, affectedVersions, activelyExploited
Jun 24, 2026

Version History

v2
Last enriched 3d ago
v2Tier C3d ago

Updated severity to CRITICAL, added affected versions 6.12.90, 6.18.32, and 7.0.9, and noted that no exploit is available.

descriptionseverityaffectedVersionsactivelyExploited
via VulDB
v13d ago

Initial creation