CyberRota Analysis
AI-GeneratedA vulnerability in the Linux kernel allows userspace applications to map the shared vmclock ABI page as read-only and subsequently upgrade it to writable, potentially leading to corruption of critical timekeeping data. This issue affects systems utilizing the vmclock ABI, and it is crucial for developers and system administrators managing Linux environments to prioritize this fix to prevent unauthorized modifications that could disrupt timekeeping functions. Immediate attention is recommended for those running virtualized environments that rely on accurate time synchronization.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: prevent read-only mappings from becoming writable vmclock_miscdev_mmap() rejects writable mappings of the shared vmclock ABI page with -EROFS, but leaves VM_MAYWRITE set. Userspace can map the page read-only and then upgrade it to writable with mprotect(), after which the guest can corrupt the host-written timekeeping data (sequence counter, UTC time, TSC offset) that the vmclock ABI defines as read-only. Clear VM_MAYWRITE on the read-only path so the mapping cannot be upgraded, as i915 does for its read-only objects and as fixed in drm/vc4 (CVE-2026-68445) and drm/panthor (CVE-2024-53071).