Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: staging: sm750fb: fix division by zero in ps_to_hz() ps_to_hz() is called from hw_sm750_crtc_set_mode() without validating that pixclock is non-zero. A zero pixclock passed via FBIOPUT_VSCREENINFO causes a division by zero. Fix by rejecting zero pixclock in lynxfb_ops_check_var(), consistent with other framebuffer drivers.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.1, < 6.6.136 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/1412ba36597a82e928f20047f41d6c6582dafe8aPatch
- https://git.kernel.org/stable/c/2f640c6043aeab31a2f607d7605271860c3b11dfPatch
- https://git.kernel.org/stable/c/6144895a4335a2491c282931f1f2fa610b86339fPatch
- https://git.kernel.org/stable/c/75a1621e4f91310673c9acbcbb25c2a7ff821cd3Patch
- https://git.kernel.org/stable/c/779412e0e391fd4a0d12e1d1adaa7bf043de62d7Patch
- https://git.kernel.org/stable/c/daf6733bd7c4c5015b431739ac29b0e29021096bPatch
FAQ
What is CVE-2026-31603?
CVE-2026-31603 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: staging: sm750fb: fix division by zero in ps_to_hz() ps_to_hz() is called from hw_sm750_crtc_set_mode() without validating that pi...
How severe is CVE-2026-31603?
CVE-2026-31603 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-31603?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.