Description
In the Linux kernel, the following vulnerability has been resolved:

ublk: clear VM_MAYWRITE on read-only ublk char device mmap

ublk_ch_mmap() rejects mmap requests with VM_WRITE set, but never
clears VM_MAYWRITE on the resulting read-only mapping. This allows
a userspace daemon to mmap the per-queue command buffer PROT_READ,
then upgrade it to PROT_WRITE via mprotect(), since VM_MAYWRITE was
never cleared.

The command buffer holds struct ublksrv_io_desc entries that are
kernel-written ABI; a writable mapping lets an unprivileged daemon
process corrupt fields such as addr, op_flags, nr_sectors, and
start_sector.

Same bug class as the drm/panthor and drm/vc4 VM_MAYWRITE fixes, and
the 2026-08-13 ptp/vmclock fix (a5edadbae57e).

Verified via mprotect() PoC: before the fix, a PROT_READ mapping can
be upgraded to PROT_READ|PROT_WRITE and a write into the command
buffer corrupts io_desc fields (confirmed under KASAN). After the
fix, mprotect() returns -EACCES.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel, a flaw in the ublk subsystem allows an unprivileged user to map the per‑queue command buffer with read permissions and then upgrade that mapping to write using mprotect. Because the VM_MAYWRITE flag is not cleared on the resulting read‑only mapping, the kernel erroneously permits the user to modify kernel‑written structures that describe I/O descriptors. Corrupting these fields can compromise kernel integrity and potentially allow the attacker to execute malicious code or gain higher privileges. This flaw effectively provides unauthorized write access to critical kernel data.

Affected Systems

All Linux kernels that include the ublk char device feature and have not yet incorporated the patch that clears the VM_MAYWRITE flag. The specific vulnerable versions are all releases prior to the committing changes in the kernel source code referenced by the advisory. The flaw affects the core Linux kernel and is disclosed for all distributions running those kernels.

Risk and Exploitability

The CVSS score of 7.8 labels this vulnerability as high severity, while the EPSS score of less than 1% indicates a low probability of exploitation in the near term, and it is not presently listed in the CISA KEV catalog. The workaround in the kernel requires a local, unprivileged user with access to a ublk device; the attacker can acquire such a user simply by running a daemon that interacts with the device. Once the mmap is upgraded to write, kernel memory corruption can occur, which is a strong indicator of privilege escalation potential. Attackers could therefore look to exploit this locals vulnerability to transition from user space to kernel space, but due to the low EPSS score and lack of widespread known exploits, the likelihood of immediate exploitation is limited.

Generated by OpenCVE AI on September 18, 2026 at 10:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the patch clearing VM_MAYWRITE on ublk mmap operations
  • If a kernel upgrade cannot be performed immediately, disable or unload the ublk module to prevent the vulnerable mmap path from being exercised
  • Restrict access to the ublk device by limiting permissions to privileged users or configuring the system to prevent unprivileged daemons from interacting with the device

Generated by OpenCVE AI on September 18, 2026 at 10:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ublk: clear VM_MAYWRITE on read-only ublk char device mmap ublk_ch_mmap() rejects mmap requests with VM_WRITE set, but never clears VM_MAYWRITE on the resulting read-only mapping. This allows a userspace daemon to mmap the per-queue command buffer PROT_READ, then upgrade it to PROT_WRITE via mprotect(), since VM_MAYWRITE was never cleared. The command buffer holds struct ublksrv_io_desc entries that are kernel-written ABI; a writable mapping lets an unprivileged daemon process corrupt fields such as addr, op_flags, nr_sectors, and start_sector. Same bug class as the drm/panthor and drm/vc4 VM_MAYWRITE fixes, and the 2026-08-13 ptp/vmclock fix (a5edadbae57e). Verified via mprotect() PoC: before the fix, a PROT_READ mapping can be upgraded to PROT_READ|PROT_WRITE and a write into the command buffer corrupts io_desc fields (confirmed under KASAN). After the fix, mprotect() returns -EACCES.
Title ublk: clear VM_MAYWRITE on read-only ublk char device mmap
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-05T05:43:08.825Z

Reserved: 2026-09-11T19:38:34.766Z

Link: CVE-2026-89793

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T10:16:55.173

Modified: 2026-10-05T06:16:59.310

Link: CVE-2026-89793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:30:07Z

Weaknesses