[PATCH] char: uv_mmtimer: prevent read-only mmtimer mapping from becoming writable
From: Abdifatah Suruur
Date: Wed Aug 19 2026 - 04:50:22 EST
uv_mmtimer_mmap() rejects writable mappings of the system-wide mmtimer
register page, but leaves VM_MAYWRITE set. Userspace can map the page
read-only and then upgrade the mapping to writable with mprotect(),
after which it can write to the shared RTC registers.
Clear VM_MAYWRITE on the read-only path, as i915 does for its read-only
objects and as fixed in drm/vc4 (CVE-2026-68445) and drm/panthor
(CVE-2024-53071) and ptp: vmclock (commit
a5edadbae57e2298a56cf7a4e774a027905a331f).
Fixes: fbd8ae106850b ("char: add SGI UV mmtimer driver")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Abdifatah Suruur <suruurism@xxxxxxxxx>
---
diff --git a/drivers/char/uv_mmtimer.c b/drivers/char/uv_mmtimer.c
index 956ebe2080a58..c8b6040f7a14c 100644
--- a/drivers/char/uv_mmtimer.c
+++ b/drivers/char/uv_mmtimer.c
@@ -154,6 +154,13 @@ static int uv_mmtimer_mmap(struct file *file, struct vm_area_struct *vma)
if (vma->vm_flags & VM_WRITE)
return -EPERM;
+ /*
+ * The mmtimer page is a system-wide read-only register page.
+ * Prevent the mapping from being upgraded to writable with
+ * mprotect().
+ */
+ vm_flags_clear(vma, VM_MAYWRITE);
+
if (PAGE_SIZE > (1 << 16))
return -ENOSYS;