Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: avoid divide-by-zero in __is_lut_linear()

__is_lut_linear() computes the expected value of each entry with

expected = i * MAX_DRM_LUT_VALUE / (size - 1);

If it is ever called with a single-entry LUT, size - 1 is zero and the
kernel takes a divide error (#DE). A LUT with fewer than two entries
cannot describe a linear mapping anyway, so return false early instead
of dividing by zero.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

In the Linux kernel, the function __is_lut_linear() calculates an expected value for each entry in a Look‑Up Table (LUT). When the table contains only one entry, the calculation divides by zero, generating a divide error exception (#DE) that can crash the kernel and cause a system reboot. This vulnerability provides a direct path to denial of service by triggering a kernel panic through a single-entry LUT, which is not a valid linear mapping and should not be processed. The weakness is a divide‑by‑zero condition, a classic reliability failure that compromises system availability.

Affected Systems

Any Linux system running a kernel version that includes the AMD display driver before the fix. The vendor is Linux (kernel) with no specific kernel version listed, so all affected kernel releases prior to the patch that compile the AMD display driver module are potentially impacted. The issue is local to the kernel and its GPU driver component for AMD hardware.

Risk and Exploitability

The vulnerability has an EPSS score of less than 1 % and is not listed in CISA’s KEV catalog, indicating a low probability of compromise. Nonetheless, the impact is severe: a triggered divide error causes an immediate kernel crash. The likely attack vector is local or requires exploitation of the GPU driver’s LUT handling, inferred from the description that the bug occurs when a single‑entry LUT is processed. An attacker with the ability to influence the LUT entries on the affected system could force a crash, but the practicality of such an attack is limited by the need for privileged or local access to the driver.

Generated by OpenCVE AI on September 18, 2026 at 09:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the patch removing the divide‑by‑zero path in __is_lut_linear()
  • If an update is not immediately available, replace or disable the AMD display driver module to eliminate the execution path that can trigger the error
  • Manually apply the upstream patch from the linked kernel commit to the current kernel source and rebuild the kernel module as an interim fix

Generated by OpenCVE AI on September 18, 2026 at 09:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-369

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: avoid divide-by-zero in __is_lut_linear() __is_lut_linear() computes the expected value of each entry with expected = i * MAX_DRM_LUT_VALUE / (size - 1); If it is ever called with a single-entry LUT, size - 1 is zero and the kernel takes a divide error (#DE). A LUT with fewer than two entries cannot describe a linear mapping anyway, so return false early instead of dividing by zero.
Title drm/amd/display: avoid divide-by-zero in __is_lut_linear()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:30:53.689Z

Reserved: 2026-09-11T19:38:34.768Z

Link: CVE-2026-89821

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:47.503

Modified: 2026-09-16T11:16:47.503

Link: CVE-2026-89821

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:45:15Z

Weaknesses