CVE-2026-89806

Summary

In the Linux kernel, the following vulnerability has been resolved:

drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation

The framebuffer size calculation fb_size = linebytes * height can overflow when both values are large (e.g., 46341 * 46341 > INT_MAX). Since linebytes and height are both int types, the multiplication is performed as int * int, which results in undefined behavior on overflow.

Use check_mul_overflow() to detect and prevent this overflow, consistent with the approach used in simpledrm.c and corebootdrm.c.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxc8a17756c42581ba1a567d1dd3b69e8f5619a7d8 < ded6ad826fe0fd059333d3a3b3e1742c8e45ff41affected
LinuxLinuxc8a17756c42581ba1a567d1dd3b69e8f5619a7d8 < d9daf9a6e7a6f82ef338a09386eefc6807100d3faffected
LinuxLinuxc8a17756c42581ba1a567d1dd3b69e8f5619a7d8 < c6f48e59ece0123f6a11527ad4d89b21c2d65b87affected
LinuxLinux6.2affected
LinuxLinux0 < 6.2unaffected
LinuxLinux6.18.51 <= 6.18.*unaffected
LinuxLinux7.2.5 <= 7.2.*unaffected
LinuxLinux7.3-rc2 <= *unaffected

Weaknesses

References