Junglewise Threat Intelligence

CVE-2026-31603: Linux Kernel division by zero in sm750fb driver

CVE-2026-31603 · Severity: medium · CVSS 5.5 · Published 2026-04-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's sm750fb display driver could allow a local user to crash the system. The issue occurs when the driver attempts to process specific display settings without verifying they are valid, leading to a system failure. This primarily impacts the availability of systems using this specific hardware driver.

Technical details

A division-by-zero vulnerability exists in the ps_to_hz() function within the sm750fb framebuffer driver (drivers/staging/sm750fb/sm750.c). The root cause is a lack of validation for the 'pixclock' variable in hw_sm750_crtc_set_mode() when provided via the FBIOPUT_VSCREENINFO ioctl. A local attacker with sufficient privileges to modify framebuffer settings can pass a zero value for pixclock, triggering the exception and causing a kernel panic or system hang. The fix implements a check in lynxfb_ops_check_var() to reject zero pixclock values with -EINVAL.

Affected products

  • Linux Linux Kernel 4.1 to 6.6.136, 6.7 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0 to 7.0.1

Timeline

  • 2026-04-24: disclosed
  • 2026-04-24: advisory
  • 2026-04-22: patched

References

Related threats