Linux Kernel: PTP VMClock ReadOnly Mapping Escalation (CVE202680724)
CVE-2026-80724 Published on August 28, 2026
ptp: vmclock: prevent read-only mappings from becoming writable
In the Linux kernel, the following vulnerability has been resolved:
ptp: vmclock: prevent read-only mappings from becoming writable
vmclock_miscdev_mmap() rejects writable mappings of the shared vmclock
ABI page with -EROFS, but leaves VM_MAYWRITE set. Userspace can map the
page read-only and then upgrade it to writable with mprotect(), after
which the guest can corrupt the host-written timekeeping data (sequence
counter, UTC time, TSC offset) that the vmclock ABI defines as read-only.
Clear VM_MAYWRITE on the read-only path so the mapping cannot be
upgraded, as i915 does for its read-only objects and as fixed in drm/vc4
(CVE-2026-68445) and drm/panthor (CVE-2024-53071).
Products Associated with CVE-2026-80724
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 20503272422693d793b84f88bf23fe4e955d3a33 and below 5b4f2bec7bea6c04084d720d731bedee7caf878d is affected.
- Version 20503272422693d793b84f88bf23fe4e955d3a33 and below 2496e141827102d6af512950057d402a2cfb2bfc is affected.
- Version 20503272422693d793b84f88bf23fe4e955d3a33 and below 2e596e7814ba38cdc129991058b6c254ed37cb11 is affected.
- Version 6.13 is affected.
- Before 6.13 is unaffected.
- Version 6.18.47, <= 6.18.* is unaffected.
- Version 7.1.11, <= 7.1.* is unaffected.
- Version 7.2.1, <= 7.2.* is unaffected.