What is CVE-2026-68445?
The resolved CVE-2026-68445 vulnerability in the Linux kernel addresses an issue in the VC4 DRM driver where a validated shader buffer object (BO) could become writable after being mapped read-only by userspace. This flaw arises because VM_MAYWRITE is not properly cleared, allowing unauthorized modification. Affected systems should apply the kernel update to mitigate the risk.
Azərbaycanca: Linux nüvəsində düzəldilmiş CVE-2026-68445 zəifliyi, VC4 DRM sürücüsündə shader bufer obyektinin (BO) yazıla bilən hala keçməsinə imkan verən problemi aradan qaldırır. Bu, istifadəçi məkanının yalnız oxunaqlı xəritələnmiş shader BO-nu sonradan yazıla bilən hala keçirə bilməsi riskini yaradır. Təsirə məruz qalan sistemlər üçün kernel yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which component of the Linux kernel is affected by CVE-2026-68445?
The CVE-2026-68445 vulnerability affects the VC4 DRM driver in the Linux kernel.
What unauthorized operation does this vulnerability allow userspace to perform?
This vulnerability allows userspace to make a read-only mapped shader buffer object (BO) become writable afterwards.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.