Executive brief
A vulnerability in the Linux kernel's DisplayLink USB frame buffer driver could allow a local user to crash the system. By providing invalid display timing information, an attacker can trigger a mathematical error that leads to a kernel crash (denial of service). This affects systems using specific USB-to-video adapters.
Technical details
A divide-by-zero vulnerability exists in the udlfb (DisplayLink) driver within the Linux kernel's fbdev subsystem. The root cause is the lack of validation for the 'pixclock' field in the fb_var_screeninfo structure when processed via the FBIOPUT_VSCREENINFO ioctl. An attacker with local access can provide a zero value for pixclock, which the driver uses directly as a divisor in dlfb_ops_check_var, resulting in a kernel panic. Patches have been released across multiple stable kernel branches to return -EINVAL when pixclock is zero.
Affected products
- Linux Linux Kernel 2.6.34 to 6.6.136, 6.7 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0 to 7.0.1
Timeline
- 2026-04-24: disclosed
- 2026-04-24: advisory
- 2026-04-09: patched: Initial patch authored by Greg Kroah-Hartman
References
- https://git.kernel.org/stable/c/03797cdee38ef19c87785622d423aabaafb71c5f
- https://git.kernel.org/stable/c/6de048d78f3029744778b7a2891745f3ca7c209a
- https://git.kernel.org/stable/c/828ce54b27de93bd9c67991bca5a2c76c76742de
- https://git.kernel.org/stable/c/9981de9fb5ae0d3d6bc5ff5ca63350c2a3cdc564
- https://git.kernel.org/stable/c/a31e4518bec70333a0a98f2946a12b53b45fe5b9
- https://git.kernel.org/stable/c/afaaaa38579f1252bb42b145f6e88a955c4f73f3
- https://git.kernel.org/stable/c/cccbf9b7fdab48ce4feb69c24f7f928aa8e4e8b8