{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.94-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.10-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  arm64: Reserve an extra page for early kernel mapping  The final part of [data, end) segment may overflow into the next page of init_pg_end[1] which is the gap page before early_init_stack[2]:  [1] crash_arm64_v9.0.1\u003e vtop ffffffed00601000 VIRTUAL           PHYSICAL ffffffed00601000  83401000  PAGE DIRECTORY: ffffffecffd62000    PGD: ffffffecffd62da0 =\u003e 10000000833fb003    PMD: ffffff80033fb018 =\u003e 10000000833fe003    PTE: ffffff80033fe008 =\u003e 68000083401f03   PAGE: 83401000       PTE        PHYSICAL  FLAGS 68000083401f03  83401000  (VALID|SHARED|AF|NG|PXN|UXN)        PAGE       PHYSICAL      MAPPING       INDEX CNT FLAGS fffffffec00d0040 83401000                0        0  1 4000 reserved  [2] ffffffed002c8000 (r) __pi__data ffffffed0054e000 (d) __pi___bss_start ffffffed005f5000 (b) __pi_init_pg_dir ffffffed005fe000 (b) __pi_init_pg_end ffffffed005ff000 (B) early_init_stack ffffffed00608000 (b) __pi__end  For 4K pages, the early kernel mapping may use 2MB block entries but the kernel segments are only 64KB aligned. Segment boundaries that fall within a 2MB block therefore require a PTE table so that different attributes can be applied on either side of the boundary.  KERNEL_SEGMENT_COUNT still correctly counts the five permanent kernel VMAs registered by declare_kernel_vmas(). However, since commit 5973a62efa34 (\"arm64: map [_text, _stext) virtual address range non-executable+read-only\"), the early mapper also maps [_text, _stext) separately from [_stext, _etext). This adds one more early-only split and can require one more page-table page than the existing EARLY_SEGMENT_EXTRA_PAGES allowance reserves.  Increase the 4K-page early mapping allowance by one page to cover that additional split.  [catalin.marinas@arm.com: rewrote part of the commit log] [catalin.marinas@arm.com: expanded the code comment]",
  "id": "DEBIAN-CVE-2026-53288",
  "modified": "2026-09-14T16:47:38.567325751Z",
  "published": "2026-06-26T20:17:21.600Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-53288"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-53288"
  ]
}