Skip to content
Critical Linux Kernel Vulnerability CVE-2026-53325 Affects Virtualization

Critical Linux Kernel Vulnerability CVE-2026-53325 Affects Virtualization

First seen 29 Jun 2026, 08:03 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 30, 2026 at 07:10 UTC
  • •CVE-2026-53325 affects the Linux kernel's AMD64 AGP driver, leading to potential system crashes.
  • •The vulnerability arises from improper error handling in the agp_amd64_probe() function.
  • •No active exploitation has been reported, but many kernel versions remain vulnerable.

CVE-2026-53325 is a critical vulnerability in the Linux kernel's AMD64 AGP driver, caused by improper error handling in the agp_amd64_probe() function. This flaw can lead to a NULL pointer dereference and General Protection Fault (GPF) when the kernel operates in virtualized environments without an AMD northbridge. The vulnerability affects a wide range of kernel versions, from 2.6.18 to the latest releases. Although the issue has been patched in recent kernel updates, many systems remain vulnerable. Currently, there is no evidence of exploitation in the wild, and it is not listed in the CISA Known Exploited Vulnerabilities catalog. The primary risk is a denial of service, as systems may crash and require rebooting, disrupting hosted workloads. No Advanced Persistent Threat (APT) groups have been linked to this vulnerability, and no proof-of-concept exploits have been published.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 93d ago How this analysis works

Timeline

2026-06-29
CVE-2026-53325 published
The vulnerability was disclosed, affecting the Linux kernel's AMD64 AGP driver in virtualized environments.
Rescana
2026-06-29
NVD entry created for CVE-2026-53325
The National Vulnerability Database published details about the vulnerability and its impact on the Linux kernel.
nvd.nist.gov

More articles in this cluster (2)

Following this threat?

Track CVE-2026-53325 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed