CVE-2026-31603

Severity CVSS v4.0:
Pending analysis
Type:
CWE-369 Divide By Zero
Publication date:
24/04/2026
Last modified:
29/04/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> staging: sm750fb: fix division by zero in ps_to_hz()<br /> <br /> ps_to_hz() is called from hw_sm750_crtc_set_mode() without validating<br /> that pixclock is non-zero. A zero pixclock passed via FBIOPUT_VSCREENINFO<br /> causes a division by zero.<br /> <br /> Fix by rejecting zero pixclock in lynxfb_ops_check_var(), consistent<br /> with other framebuffer drivers.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.1 (including) 6.6.136 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.83 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.24 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 6.19.14 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 7.0 (including) 7.0.1 (excluding)