Executive brief
A vulnerability in the Linux kernel's sm750fb display driver could allow a local user to crash the system. The issue occurs when the driver attempts to process specific display settings without verifying they are valid, leading to a system failure. This primarily impacts the availability of systems using this specific hardware driver.
Technical details
A division-by-zero vulnerability exists in the ps_to_hz() function within the sm750fb framebuffer driver (drivers/staging/sm750fb/sm750.c). The root cause is a lack of validation for the 'pixclock' variable in hw_sm750_crtc_set_mode() when provided via the FBIOPUT_VSCREENINFO ioctl. A local attacker with sufficient privileges to modify framebuffer settings can pass a zero value for pixclock, triggering the exception and causing a kernel panic or system hang. The fix implements a check in lynxfb_ops_check_var() to reject zero pixclock values with -EINVAL.
Affected products
- Linux Linux Kernel 4.1 to 6.6.136, 6.7 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0 to 7.0.1
Timeline
- 2026-04-24: disclosed
- 2026-04-24: advisory
- 2026-04-22: patched
References
- https://git.kernel.org/stable/c/124a43550db8a74eef080cd4573a4904efe67029
- https://git.kernel.org/stable/c/1412ba36597a82e928f20047f41d6c6582dafe8a
- https://git.kernel.org/stable/c/2f640c6043aeab31a2f607d7605271860c3b11df
- https://git.kernel.org/stable/c/3300b049693138852a4c6738b5f1194a1ee91ddd
- https://git.kernel.org/stable/c/6144895a4335a2491c282931f1f2fa610b86339f
- https://git.kernel.org/stable/c/75a1621e4f91310673c9acbcbb25c2a7ff821cd3
- https://git.kernel.org/stable/c/779412e0e391fd4a0d12e1d1adaa7bf043de62d7