Linux Kernel Vulnerability Affecting Virtual Clock Management
CVE-2026-80724

8.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
28 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-80724?

A vulnerability in the Linux kernel's virtual clock management allows userspace to exploit read-only memory mappings. By mapping the shared vmclock ABI page as read-only, an attacker could subsequently elevate it to writable using mprotect(). This alteration poses a risk as it may corrupt critical host-written timekeeping data, including the sequence counter and UTC time. The issue arises since the function responsible for memory mapping retains a VM_MAYWRITE flag for read-only mappings, enabling the potential for data corruption. This vulnerability has been addressed to ensure that read-only paths correctly clear the flag, preventing such escalation.

Affected Version(s)

Linux 20503272422693d793b84f88bf23fe4e955d3a33 < 5b4f2bec7bea6c04084d720d731bedee7caf878d

Linux 20503272422693d793b84f88bf23fe4e955d3a33 < 3f5677d2f817355147337f0453174c7bb0f3b66a

Linux 20503272422693d793b84f88bf23fe4e955d3a33 < 2496e141827102d6af512950057d402a2cfb2bfc

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.