AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-68445

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of validated shader buffer objects (BOs) in the vc4 driver, allowing userspace to potentially modify shader code after it has been validated. This could lead to unauthorized code execution on the GPU, undermining the integrity of the graphics processing pipeline. Organizations using Linux systems with the vc4 driver, particularly those relying on GPU-accelerated applications, should prioritize addressing this issue to maintain security and prevent exploitation.

CVE
CVE-2026-68445
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Prevent shader BO mappings from becoming writable vc4_gem_object_mmap() rejects a writable mapping of a validated shader BO, but leaves VM_MAYWRITE set. Userspace can map the BO read-only and then turn it writable with mprotect(). Validated shader BOs must stay read-only: the validator checks the instructions once and the GPU trusts them afterwards. A writable mapping lets userspace rewrite the code after validation, bypassing the validator. Clear VM_MAYWRITE on the read-only path so the mapping cannot be upgraded, as i915 already does for its read-only objects.