{"id":"CVE-2026-80724","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nptp: vmclock: prevent read-only mappings from becoming writable\n\nvmclock_miscdev_mmap() rejects writable mappings of the shared vmclock\nABI page with -EROFS, but leaves…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nptp: vmclock: prevent read-only mappings from becoming writable\n\nvmclock_miscdev_mmap() rejects writable mappings of the shared vmclock\nABI page with -EROFS, but leaves…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= 20503272422693d793b84f88bf23fe4e955d3a33 < 5b4f2bec7bea6c04084d720d731bedee7caf878d","Linux >= 20503272422693d793b84f88bf23fe4e955d3a33 < 3f5677d2f817355147337f0453174c7bb0f3b66a","Linux >= 20503272422693d793b84f88bf23fe4e955d3a33 < 2496e141827102d6af512950057d402a2cfb2bfc","Linux >= 20503272422693d793b84f88bf23fe4e955d3a33 < 2e596e7814ba38cdc129991058b6c254ed37cb11","Linux >= 20503272422693d793b84f88bf23fe4e955d3a33 < 0ce59c4148ecd1520c5592a63bb3c8991ee2d326","Linux >= 20503272422693d793b84f88bf23fe4e955d3a33 < a5edadbae57e2298a56cf7a4e774a027905a331f","Linux 6.13"],"published":"2026-08-28","updated":"2026-09-07","sourceUpdated":"2026-09-07T16:17:29.930","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80724","references":[{"url":"https://git.kernel.org/stable/c/0ce59c4148ecd1520c5592a63bb3c8991ee2d326","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2496e141827102d6af512950057d402a2cfb2bfc","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2e596e7814ba38cdc129991058b6c254ed37cb11","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3f5677d2f817355147337f0453174c7bb0f3b66a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5b4f2bec7bea6c04084d720d731bedee7caf878d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a5edadbae57e2298a56cf7a4e774a027905a331f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org","exploit-available"],"epss":0.0012,"epssPercentile":0.02104,"exploits":{"github":1,"githubRepos":["https://github.com/suruurism/cve-writeups-and-pocs"],"checkedAt":"2026-09-23T07:14:54.214Z"},"exploitAvailable":true,"ingestedAt":"2026-08-31T08:05:08.586Z","slug":"CVE-2026-80724","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nptp: vmclock: prevent read-only mappings from becoming writable\n\nvmclock_miscdev_mmap() rejects writable mappings of the shared vmclock\nABI page with -EROFS, but leaves VM_MAYWRITE set.  Userspace can map the\npage read-only and then upgrade it to writable with mprotect(), after\nwhich the guest can corrupt the host-written timekeeping data (sequence\ncounter, UTC time, TSC offset) that the vmclock ABI defines as read-only.\n\nClear VM_MAYWRITE on the read-only path so the mapping cannot be\nupgraded, as i915 does for its read-only objects and as fixed in drm/vc4\n(CVE-2026-68445) and drm/panthor (CVE-2024-53071).\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":60,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":5492,"id":"CVE-2026-80724","ts":1788887289441,"field":"exploit_available","old":"false","new":"true"},{"seq":4370,"id":"CVE-2026-80724","ts":1788886401858,"field":"exploit_available","old":"true","new":"false"},{"seq":3086,"id":"CVE-2026-80724","ts":1788883065714,"field":"exploit_available","old":"false","new":"true"},{"seq":2115,"id":"CVE-2026-80724","ts":1788882469964,"field":"exploit_available","old":"true","new":"false"},{"seq":266,"id":"CVE-2026-80724","ts":1788881644419,"field":"exploit_available","old":"false","new":"true"}]}