Junglewise Threat Intelligence

CVE-2026-68445: Linux kernel drm/vc4 shader memory protection bypass via mprotect

CVE-2026-68445 · Severity: high · CVSS 7.8 · Published 2026-08-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's vc4 graphics driver validates GPU shader code once and then trusts it. A bug allowed userspace to map validated shaders as read-only initially, then upgrade them to writable using mprotect(), letting attackers rewrite shader instructions after validation and execute arbitrary GPU code. This affects systems using Broadcom VideoCore IV graphics hardware (primarily Raspberry Pi devices).

Technical details

The vulnerability is a memory protection bypass in the vc4_gem_object_mmap() function within the DRM (Direct Rendering Manager) driver for Broadcom VideoCore IV GPU. The function correctly rejected initial writable mappings of validated shader buffer objects (BOs) but failed to clear the VM_MAYWRITE flag, leaving the virtual memory area upgradeable. Userspace could exploit this by mapping a validated shader read-only and then calling mprotect() to escalate the mapping to writable, bypassing the shader validator which only performs a single-pass inspection. The fix clears VM_MAYWRITE on read-only shader BO paths, preventing mprotect()-based upgrade attacks. The vulnerability affects Linux kernels from version 4.2 onward (when shader BO validation was introduced) up to the patched versions; the fix is available in upstream and stable kernel releases.

Affected products

  • Linux Linux kernel 4.2 and later (prior to patch)

Timeline

  • 2026-08-12: disclosed
  • 2026-07-21: patched

References

Related threats