CVE-2026-63935

Summary

In the Linux kernel, the following vulnerability has been resolved:

iio: adc: nxp-sar-adc: fix division by zero in write_raw

Add a validation check for the sampling frequency value before using it as a divisor. A user writing zero or a negative value to the sampling_frequency sysfs attribute triggers a division by zero in the kernel.

Also prevent unsigned integer underflow when the computed cycle count is smaller than NXP_SAR_ADC_CONV_TIME, which would wrap the u32 inpsamp to a huge value.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux4434072a893e4864519c167947083ff3e4cc2d95 < cb6ea15e7d3c7518f806975a06b7d4c0a26402eaaffected
LinuxLinux4434072a893e4864519c167947083ff3e4cc2d95 < a9aba21a539c668a66b58eeb08ad3909e5a54c2aaffected
LinuxLinux7.0affected
LinuxLinux0 < 7.0unaffected
LinuxLinux7.0.12 <= 7.0.*unaffected
LinuxLinux7.1 <= *unaffected

Weaknesses

References