{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80724","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.788Z","datePublished":"2026-08-28T07:03:08.410Z","dateUpdated":"2026-09-07T15:45:07.221Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-07T15:45:07.221Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nptp: vmclock: prevent read-only mappings from becoming writable\n\nvmclock_miscdev_mmap() rejects writable mappings of the shared vmclock\nABI page with -EROFS, but leaves VM_MAYWRITE set.  Userspace can map the\npage read-only and then upgrade it to writable with mprotect(), after\nwhich the guest can corrupt the host-written timekeeping data (sequence\ncounter, UTC time, TSC offset) that the vmclock ABI defines as read-only.\n\nClear VM_MAYWRITE on the read-only path so the mapping cannot be\nupgraded, as i915 does for its read-only objects and as fixed in drm/vc4\n(CVE-2026-68445) and drm/panthor (CVE-2024-53071)."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Exploitation requires local syscalls to open /dev/vmclock0, mmap the shared ABI page read-only, mprotect it writable, and write host-authoritative fields; there is no network, Bluetooth, or physical-device path to vmclock_miscdev_mmap().\nAC:L - Any process that can open the misc device can reliably mmap(PROT_READ), mprotect(PROT_WRITE), and corrupt the page without races, special memory layout, or timing; VM_MAYWRITE left set is the sole missing check and mprotect honors it per mm/mprotect.c.\nPR:L - vmclock_miscdev_open() performs no capability checks; AWS ClockBound documents chmod a+r on /dev/vmclock0 for unprivileged latency-sensitive apps on EC2/Amazon Linux, so a normal tenant user on affected cloud VMs can reach the bug without root or user-namespace admin caps.\nUI:N - The attacker process performs the full open/mmap/mprotect/write sequence itself; no victim mount, click, or other user action is required beyond the attacker already having local shell access.\nS:C - The vmclock ABI page is hypervisor-written shared memory whose seq_count, UTC time, and TSC offset must stay guest-read-only; mprotect bypass lets a guest user corrupt that host-authoritative data, crossing the guest/hypervisor trust boundary rather than staying within guest-kernel scope alone.\nC:H - Unauthorized writes let an attacker race seq_count updates and corrupt in-flight host-populated fields, yielding torn reads of timekeeping data to other guest consumers and potentially exposing transient host-written values that read-only mmap alone would not reliably observe.\nI:H - After mprotect, the attacker gains arbitrary modification of host-written vmclock_abi fields (seq_count, disruption_marker, counter_value, time_sec, flags), breaking integrity of authoritative timekeeping and migration/disruption signaling relied on by guest kernel PTP and userspace ClockBound consumers.\nA:H - Corrupting seq_count, clock_status, or disruption/vm_generation markers can force ETIMEDOUT/-EINVAL in vmclock_get_crosststamp, trigger false migration/disruption handling, and cause latency-sensitive services to withdraw or fail, producing severe availability loss on affected cloud VMs."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/ptp/ptp_vmclock.c"],"versions":[{"version":"20503272422693d793b84f88bf23fe4e955d3a33","lessThan":"5b4f2bec7bea6c04084d720d731bedee7caf878d","status":"affected","versionType":"git"},{"version":"20503272422693d793b84f88bf23fe4e955d3a33","lessThan":"3f5677d2f817355147337f0453174c7bb0f3b66a","status":"affected","versionType":"git"},{"version":"20503272422693d793b84f88bf23fe4e955d3a33","lessThan":"2496e141827102d6af512950057d402a2cfb2bfc","status":"affected","versionType":"git"},{"version":"20503272422693d793b84f88bf23fe4e955d3a33","lessThan":"2e596e7814ba38cdc129991058b6c254ed37cb11","status":"affected","versionType":"git"},{"version":"20503272422693d793b84f88bf23fe4e955d3a33","lessThan":"0ce59c4148ecd1520c5592a63bb3c8991ee2d326","status":"affected","versionType":"git"},{"version":"20503272422693d793b84f88bf23fe4e955d3a33","lessThan":"a5edadbae57e2298a56cf7a4e774a027905a331f","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/ptp/ptp_vmclock.c"],"versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","status":"unaffected","versionType":"semver"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"6.18.47"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"7.1.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"7.2.1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/5b4f2bec7bea6c04084d720d731bedee7caf878d"},{"url":"https://git.kernel.org/stable/c/3f5677d2f817355147337f0453174c7bb0f3b66a"},{"url":"https://git.kernel.org/stable/c/2496e141827102d6af512950057d402a2cfb2bfc"},{"url":"https://git.kernel.org/stable/c/2e596e7814ba38cdc129991058b6c254ed37cb11"},{"url":"https://git.kernel.org/stable/c/0ce59c4148ecd1520c5592a63bb3c8991ee2d326"},{"url":"https://git.kernel.org/stable/c/a5edadbae57e2298a56cf7a4e774a027905a331f"}],"title":"ptp: vmclock: prevent read-only mappings from becoming writable","x_generator":{"engine":"bippy-1.2.0"}}}}