Executive brief
A vulnerability in the Linux kernel's driver for the ADIS16260 digital gyroscope could allow a local user to crash the system. By providing an invalid value (zero) to the device's sampling frequency setting, a user can trigger a 'division by zero' error in the kernel. This results in a system crash or instability, impacting the availability of the affected device or the entire operating system.
Technical details
A division by zero vulnerability exists in the adis16260_write_raw function within drivers/iio/gyro/adis16260.c of the Linux kernel. The issue stems from a lack of validation for the sampling frequency value provided via the sampling_frequency sysfs attribute. When a user writes a value of zero to this attribute, the kernel uses it as a divisor in a calculation (e.g., t = 256 / val), leading to a kernel panic or oops. This is a local attack vector requiring access to the sysfs interface. The vulnerability has been patched by adding a check to ensure the frequency value is greater than zero before proceeding with the division.
Affected products
- Linux Linux 2.6.35 to 6.6.143
Timeline
- 2026-03-31: disclosed: Initial patch authored
- 2026-04-28: patched: Patch committed to mainline kernel
- 2026-07-19: advisory: CVE-2026-63933 published
References
- https://git.kernel.org/stable/c/19eb8565c4500f9af17ec65eaf952365e2893351
- https://git.kernel.org/stable/c/59f80b945f2ca645064074d8507785c26ea16d2d
- https://git.kernel.org/stable/c/5a42e39606b9bd6b40ed02bdfd04fe179d6173f4
- https://git.kernel.org/stable/c/761e8b489e6cf166c574034b70637f8a7eadd0ee
- https://git.kernel.org/stable/c/86298fb6829cab983910810959f85d4b4fd0f5c1
- https://git.kernel.org/stable/c/aa8a5e118e97d2cfd0da5ea4f8f0f488efdea4b0
- https://git.kernel.org/stable/c/aaf9d640e9ae1172d0a9c659ecb245a50a10850a