CVE-2026-68445 PUBLISHED

drm/vc4: Prevent shader BO mappings from becoming writable

Assigner: Linux
Reserved: 30.07.2026 Published: 12.08.2026 Updated: 12.08.2026

In the Linux kernel, the following vulnerability has been resolved:

drm/vc4: Prevent shader BO mappings from becoming writable

vc4_gem_object_mmap() rejects a writable mapping of a validated shader BO, but leaves VM_MAYWRITE set. Userspace can map the BO read-only and then turn it writable with mprotect().

Validated shader BOs must stay read-only: the validator checks the instructions once and the GPU trusts them afterwards. A writable mapping lets userspace rewrite the code after validation, bypassing the validator.

Clear VM_MAYWRITE on the read-only path so the mapping cannot be upgraded, as i915 already does for its read-only objects.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 463873d5701427f2964a0b4b72c45f1f14b6df87 to 9f0ee411fc2d76333d6087c5862ffa907cf7a175 (excl.)
  • affected from 463873d5701427f2964a0b4b72c45f1f14b6df87 to 019e6ad247f7fd038d2e009789f6d9bfcccb1ae7 (excl.)
  • affected from 463873d5701427f2964a0b4b72c45f1f14b6df87 to 6deaa317201851c644c431b57682e54d06b35838 (excl.)
  • affected from 463873d5701427f2964a0b4b72c45f1f14b6df87 to fe168ef1d232d734d9998fd74822e2e20930dfff (excl.)
  • affected from 463873d5701427f2964a0b4b72c45f1f14b6df87 to 0c9e6367639548307d3f578f6943ce72c9d39087 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 4.5 is affected
  • unaffected from 0 to 4.5 (excl.)
  • unaffected from 6.6.148 to 6.6.* (incl.)
  • unaffected from 6.12.101 to 6.12.* (incl.)
  • unaffected from 6.18.42 to 6.18.* (incl.)
  • unaffected from 7.1.6 to 7.1.* (incl.)
  • unaffected from 7.2-rc5 to * (incl.)

References