{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-68445","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-30T09:28:09.394Z","datePublished":"2026-08-12T00:07:36.230Z","dateUpdated":"2026-08-17T05:05:42.989Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T05:05:42.989Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vc4: Prevent shader BO mappings from becoming writable\n\nvc4_gem_object_mmap() rejects a writable mapping of a validated shader\nBO, but leaves VM_MAYWRITE set.  Userspace can map the BO read-only and\nthen turn it writable with mprotect().\n\nValidated shader BOs must stay read-only: the validator checks the\ninstructions once and the GPU trusts them afterwards.  A writable\nmapping lets userspace rewrite the code after validation, bypassing the\nvalidator.\n\nClear VM_MAYWRITE on the read-only path so the mapping cannot be\nupgraded, as i915 already does for its read-only objects."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Exploitation requires local access to the vc4 DRM render node (/dev/dri/renderD*) to issue VC4_CREATE_SHADER_BO, VC4_MMAP_BO, mmap/mprotect and VC4_SUBMIT_CL; there is no remote or network-facing path to this code.\nAC:L - The attacker fully controls every step: create a shader that passes validation, map it PROT_READ, upgrade it with mprotect(PROT_WRITE), rewrite the instructions and submit. There is no race, no memory-layout dependency, and it works on the default configuration of any VC4 (Raspberry Pi) system.\nPR:L - VC4_CREATE_SHADER_BO, VC4_MMAP_BO and VC4_SUBMIT_CL are all DRM_RENDER_ALLOW ioctls, so an ordinary unprivileged user with render-node access (the default for logged-in/graphical users on Raspberry Pi and embedded VC4 devices) can perform the whole sequence. No capability check is involved.\nUI:N - The attacking process performs the entire sequence itself; no action by another user or administrator is needed.\nS:U - The vulnerable driver and the compromised resource (kernel/system memory) are both under the kernel's security authority; this is a standard local kernel privilege escalation rather than a VM or hypervisor boundary escape.\nC:H - Post-validation rewriting of shader code lets the GPU, which has no IOMMU on VC4, read arbitrary system memory via texture, uniform and direct-addressed TMU lookups — exactly the disclosure the validator exists to prevent, giving arbitrary kernel memory read.\nI:H - Unvalidated QPU code can use the VPM write address register in general-purpose DMA mode to write to arbitrary physical addresses, an arbitrary kernel-memory write primitive that yields full privilege escalation and code execution.\nA:H - The same arbitrary DMA writes and unbounded shader execution readily corrupt kernel structures or hang the GPU, causing kernel panics or a full system hang triggerable at will by an unprivileged user."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/vc4/vc4_bo.c"],"versions":[{"version":"463873d5701427f2964a0b4b72c45f1f14b6df87","lessThan":"9f0ee411fc2d76333d6087c5862ffa907cf7a175","status":"affected","versionType":"git"},{"version":"463873d5701427f2964a0b4b72c45f1f14b6df87","lessThan":"019e6ad247f7fd038d2e009789f6d9bfcccb1ae7","status":"affected","versionType":"git"},{"version":"463873d5701427f2964a0b4b72c45f1f14b6df87","lessThan":"6deaa317201851c644c431b57682e54d06b35838","status":"affected","versionType":"git"},{"version":"463873d5701427f2964a0b4b72c45f1f14b6df87","lessThan":"fe168ef1d232d734d9998fd74822e2e20930dfff","status":"affected","versionType":"git"},{"version":"463873d5701427f2964a0b4b72c45f1f14b6df87","lessThan":"0c9e6367639548307d3f578f6943ce72c9d39087","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/vc4/vc4_bo.c"],"versions":[{"version":"4.5","status":"affected"},{"version":"0","lessThan":"4.5","status":"unaffected","versionType":"semver"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.5","versionEndExcluding":"6.6.148"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.5","versionEndExcluding":"6.12.101"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.5","versionEndExcluding":"6.18.42"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.5","versionEndExcluding":"7.1.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.5","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/9f0ee411fc2d76333d6087c5862ffa907cf7a175"},{"url":"https://git.kernel.org/stable/c/019e6ad247f7fd038d2e009789f6d9bfcccb1ae7"},{"url":"https://git.kernel.org/stable/c/6deaa317201851c644c431b57682e54d06b35838"},{"url":"https://git.kernel.org/stable/c/fe168ef1d232d734d9998fd74822e2e20930dfff"},{"url":"https://git.kernel.org/stable/c/0c9e6367639548307d3f578f6943ce72c9d39087"}],"title":"drm/vc4: Prevent shader BO mappings from becoming writable","x_generator":{"engine":"bippy-1.2.0"}}}}