CVE-2026-80724 (GCVE-0-2026-80724)
Vulnerability from cvelistv5
Published
2026-08-28 07:03
Modified
2026-08-29 06:22
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ptp: vmclock: prevent read-only mappings from becoming writable
vmclock_miscdev_mmap() rejects writable mappings of the shared vmclock
ABI page with -EROFS, but leaves VM_MAYWRITE set. Userspace can map the
page read-only and then upgrade it to writable with mprotect(), after
which the guest can corrupt the host-written timekeeping data (sequence
counter, UTC time, TSC offset) that the vmclock ABI defines as read-only.
Clear VM_MAYWRITE on the read-only path so the mapping cannot be
upgraded, as i915 does for its read-only objects and as fixed in drm/vc4
(CVE-2026-68445) and drm/panthor (CVE-2024-53071).
References
Impacted products
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/ptp/ptp_vmclock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5b4f2bec7bea6c04084d720d731bedee7caf878d",
"status": "affected",
"version": "20503272422693d793b84f88bf23fe4e955d3a33",
"versionType": "git"
},
{
"lessThan": "2496e141827102d6af512950057d402a2cfb2bfc",
"status": "affected",
"version": "20503272422693d793b84f88bf23fe4e955d3a33",
"versionType": "git"
},
{
"lessThan": "2e596e7814ba38cdc129991058b6c254ed37cb11",
"status": "affected",
"version": "20503272422693d793b84f88bf23fe4e955d3a33",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/ptp/ptp_vmclock.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.13"
},
{
"lessThan": "6.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "6.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nptp: vmclock: prevent read-only mappings from becoming writable\n\nvmclock_miscdev_mmap() rejects writable mappings of the shared vmclock\nABI page with -EROFS, but leaves VM_MAYWRITE set. Userspace can map the\npage read-only and then upgrade it to writable with mprotect(), after\nwhich the guest can corrupt the host-written timekeeping data (sequence\ncounter, UTC time, TSC offset) that the vmclock ABI defines as read-only.\n\nClear VM_MAYWRITE on the read-only path so the mapping cannot be\nupgraded, as i915 does for its read-only objects and as fixed in drm/vc4\n(CVE-2026-68445) and drm/panthor (CVE-2024-53071)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires local syscalls to open /dev/vmclock0, mmap the shared ABI page read-only, mprotect it writable, and write host-authoritative fields; there is no network, Bluetooth, or physical-device path to vmclock_miscdev_mmap().\nAC:L - Any process that can open the misc device can reliably mmap(PROT_READ), mprotect(PROT_WRITE), and corrupt the page without races, special memory layout, or timing; VM_MAYWRITE left set is the sole missing check and mprotect honors it per mm/mprotect.c.\nPR:L - vmclock_miscdev_open() performs no capability checks; AWS ClockBound documents chmod a+r on /dev/vmclock0 for unprivileged latency-sensitive apps on EC2/Amazon Linux, so a normal tenant user on affected cloud VMs can reach the bug without root or user-namespace admin caps.\nUI:N - The attacker process performs the full open/mmap/mprotect/write sequence itself; no victim mount, click, or other user action is required beyond the attacker already having local shell access.\nS:C - The vmclock ABI page is hypervisor-written shared memory whose seq_count, UTC time, and TSC offset must stay guest-read-only; mprotect bypass lets a guest user corrupt that host-authoritative data, crossing the guest/hypervisor trust boundary rather than staying within guest-kernel scope alone.\nC:H - Unauthorized writes let an attacker race seq_count updates and corrupt in-flight host-populated fields, yielding torn reads of timekeeping data to other guest consumers and potentially exposing transient host-written values that read-only mmap alone would not reliably observe.\nI:H - After mprotect, the attacker gains arbitrary modification of host-written vmclock_abi fields (seq_count, disruption_marker, counter_value, time_sec, flags), breaking integrity of authoritative timekeeping and migration/disruption signaling relied on by guest kernel PTP and userspace ClockBound consumers.\nA:H - Corrupting seq_count, clock_status, or disruption/vm_generation markers can force ETIMEDOUT/-EINVAL in vmclock_get_crosststamp, trigger false migration/disruption handling, and cause latency-sensitive services to withdraw or fail, producing severe availability loss on affected cloud VMs."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-29T06:22:41.352Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5b4f2bec7bea6c04084d720d731bedee7caf878d"
},
{
"url": "https://git.kernel.org/stable/c/2496e141827102d6af512950057d402a2cfb2bfc"
},
{
"url": "https://git.kernel.org/stable/c/2e596e7814ba38cdc129991058b6c254ed37cb11"
}
],
"title": "ptp: vmclock: prevent read-only mappings from becoming writable",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80724",
"datePublished": "2026-08-28T07:03:08.410Z",
"dateReserved": "2026-08-26T14:34:25.788Z",
"dateUpdated": "2026-08-29T06:22:41.352Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…