Executive brief
A vulnerability in the Linux kernel's display driver component could allow a local user to crash the system. The issue occurs when the system processes specific display configuration requests, leading to a 'divide-by-zero' error. This results in a denial-of-service, potentially disrupting operations or causing data loss for unsaved work.
Technical details
A divide-by-zero vulnerability exists in the Linux kernel's fbdev subsystem, specifically within the tdfxfb and udlfb drivers. The root cause is the lack of validation for the 'pixclock' value in the fb_var_screeninfo structure when processing the FBIOPUT_VSCREENINFO ioctl. A local attacker with sufficient privileges to access the framebuffer device can provide a zero value for pixclock, triggering a kernel panic. The vulnerability has been addressed by adding a check to ensure pixclock is non-zero in tdfxfb_check_var. Patches are available across multiple stable kernel branches including 6.6.y, 6.12.y, 6.19.y, and 7.0.y.
Affected products
- Linux Linux Kernel versions from 2.6.12.1 up to (excluding) 6.6.136; 6.7 up to (excluding) 6.12.83; 6.13 up to (excluding) 6.18.24; 6.19 up to (excluding) 6.19.14; 7.0 up to (excluding) 7.0.1
Timeline
- 2026-04-24: disclosed
- 2026-04-24: advisory
- 2026-04-22: patched: Initial patches applied to stable branches.
References
- https://git.kernel.org/stable/c/2f207e46c62688bb7eb4e3feaf9a0d94020fb0c9
- https://git.kernel.org/stable/c/53cb4e79a07124d2ebe502983c29800104080b47
- https://git.kernel.org/stable/c/59bde9e0930efef1286768cb65fc78d5e5267f93
- https://git.kernel.org/stable/c/63dfb0b4741f46d65b667c4275132b3d1966acc8
- https://git.kernel.org/stable/c/6567d3e1aaadfebf44ce7dc9ea2630323cd4c736
- https://git.kernel.org/stable/c/6c05191598eca87a87329b3f6e4a0825775f09cf
- https://git.kernel.org/stable/c/859a239d58a812b61267d9944b701affe6a6244e