Description
In the Linux kernel, the following vulnerability has been resolved:

drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation

The framebuffer size calculation `fb_size = linebytes * height` can
overflow when both values are large (e.g., 46341 * 46341 > INT_MAX).
Since linebytes and height are both int types, the multiplication is
performed as int * int, which results in undefined behavior on overflow.

Use check_mul_overflow() to detect and prevent this overflow, consistent
with the approach used in simpledrm.c and corebootdrm.c.
Published: 2026-09-16
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Memory Corruption
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel’s DRM subsystem in the sysfb driver contains an integer overflow in the calculation of framebuffer size. The calculation fb_size = linebytes * height uses int operands; if both linebytes and height are large, multiplication can exceed INT_MAX, triggering undefined behavior. This overflow allows an attacker to potentially influence how kernel memory is allocated or accessed for framebuffers, leading to kernel memory corruption and possible privilege escalation.

Affected Systems

The issue exists in the Linux kernel’s DRM subsystem, specifically the sysfb driver’s ofdrm configuration. All Linux distributions that ship a kernel version prior to the stable commit adding check_mul_overflow() are affected. The change is part of the generic Linux kernel; no specific vendor scope beyond the Linux kernel itself.

Risk and Exploitability

The CVSS score of 8.4 indicates high severity, and the EPSS score of less than 1% shows a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation documented yet. Based on the description, it is inferred that an attacker would need to trigger the framebuffer size calculation with large dimensions—i.e., influence the linebytes and height values—through a local or privileged interface such as a graphics driver or ioctl. This suggests the attack vector is likely local or requires elevated privileges, and from the overflow it may lead to arbitrary kernel memory writes and privilege escalation.

Generated by OpenCVE AI on September 18, 2026 at 10:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that includes the check_mul_overflow() patch for the ofdrm framebuffer size calculation.
  • If updating is not immediately possible, disable or remove the ofdrm framebuffer driver from the kernel configuration to eliminate the vulnerable code path.
  • Monitor logs for framebuffer-related kernel panics or corruption that could indicate exploitation.

Generated by OpenCVE AI on September 18, 2026 at 10:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Fri, 18 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation The framebuffer size calculation `fb_size = linebytes * height` can overflow when both values are large (e.g., 46341 * 46341 > INT_MAX). Since linebytes and height are both int types, the multiplication is performed as int * int, which results in undefined behavior on overflow. Use check_mul_overflow() to detect and prevent this overflow, consistent with the approach used in simpledrm.c and corebootdrm.c.
Title drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:56:42.335Z

Reserved: 2026-09-11T19:38:34.767Z

Link: CVE-2026-89806

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:45.703

Modified: 2026-10-03T11:17:43.843

Link: CVE-2026-89806

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T11:00:09Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound