Record summary

CVE-2026-68445 has a selected CVSS score of 7.8 (high).

Description

In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Prevent shader BO mappings from becoming writable vc4_gem_object_mmap() rejects a writable mapping of a validated shader BO, but leaves VM_MAYWRITE set. Userspace can map the BO read-only and then turn it writable with mprotect(). Validated shader BOs must stay read-only: the validator checks the instructions once and the GPU trusts them afterwards. A writable mapping lets userspace rewrite the code after validation, bypassing the validator. Clear VM_MAYWRITE on the read-only path so the mapping cannot be upgraded, as i915 already does for its read-only objects.

Description source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected, affected

CVE List463873d5701427f2964a0b4b72c45f1f14b6df87 to < 9f0ee411fc2d76333d6087c5862ffa907cf7a175affected
463873d5701427f2964a0b4b72c45f1f14b6df87 to < 019e6ad247f7fd038d2e009789f6d9bfcccb1ae7affected
463873d5701427f2964a0b4b72c45f1f14b6df87 to < 6deaa317201851c644c431b57682e54d06b35838affected
463873d5701427f2964a0b4b72c45f1f14b6df87 to < fe168ef1d232d734d9998fd74822e2e20930dfffaffected
463873d5701427f2964a0b4b72c45f1f14b6df87 to < 0c9e6367639548307d3f578f6943ce72c9d39087affected
4.5affected
Before 4.5unaffected
6.6.148 to ≤ 6.6.*unaffected
6.12.101 to ≤ 6.12.*unaffected
6.18.42 to ≤ 6.18.*unaffected
7.1.6 to ≤ 7.1.*unaffected
7.2-rc5 to ≤ *unaffected
OSV4.5.0 to < 6.6.148 · Fixed in 6.6.148affected
6.7.0 to < 6.12.101 · Fixed in 6.12.101affected
6.13.0 to < 6.18.42 · Fixed in 6.18.42affected
6.19.0 to < 7.1.6 · Fixed in 7.1.6affected

References

8