Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: fix division by zero in get_estimated_bw()

get_estimated_bw() divides by link->dpia_bw_alloc_config.bw_granularity,
which is zeroed by reset_bw_alloc_struct() and only populated once
DP_TUNNELING_BW_ALLOC_CAP_CHANGED has been handled.

link_dp_dpia_handle_bw_alloc_status(), the DPCD interrupt handler,
calls get_estimated_bw() whenever DP_TUNNELING_ESTIMATED_BW_CHANGED
is set, independently of whether DP_TUNNELING_BW_ALLOC_CAP_CHANGED
has ever fired for that link. A connected USB4/DPIA tunneling device
that reports an estimated-bandwidth change before ever reporting a
capability change drives a division by zero in this IRQ path.

link_dpia_send_bw_alloc_request() already guards the same
bw_granularity division; add the identical guard here rather than
introducing a new pattern.

(cherry picked from commit f2a961457c33dc34223aad5c9e8971de34a4eed3)
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (kernel crash)
Action: Patch
AI Analysis

Impact

The Linux kernel drm/amd/display subsystem contains a division by zero bug in get_estimated_bw(). The function divides the bandwidth allocation granularity by link->dpia_bw_alloc_config.bw_granularity, which remains zero unless a capability change has been processed. If a USB4/DPIA tunneling device reports an estimated‑bandwidth change before reporting a capability change, an IRQ handler will trigger this division by zero, leading to a kernel fault and system crash. This is a pure runtime error that can be triggered when the device is connected.

Affected Systems

All Linux kernel versions that include the drm/amd/display driver prior to the fix, regardless of distribution, are affected. The issue appears in the AMD display DRM infrastructure used by many modern systems. No specific kernel version range is listed, but any kernel with the unpatched AMD display component is vulnerable.

Risk and Exploitability

The EPSS score indicates a probability of exploitation in the <1% range, and the vulnerability is not listed in CISA’s KEV catalog. The path to exploitation is local: a faulty USB4/DPIA tunneling device must be connected to the target system. Because the flaw triggers only during certain interrupt handling, the attack surface is limited. The impact is a denial of service via kernel panic, with no remote code execution or persistence possible.

Generated by OpenCVE AI on September 18, 2026 at 04:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that includes the commit f2a961457c33dc34223aad5c9e8971de34a4eed3, which removes the division by zero.
  • If a kernel update is not yet available, avoid connecting USB4/DPIA tunneling devices until the patch is applied or use firmware settings to disable the affected IRQ handling path in the driver.
  • Reboot the system after any kernel update to ensure the new module is loaded and to clear the vulnerability.

Generated by OpenCVE AI on September 18, 2026 at 04:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-369

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix division by zero in get_estimated_bw() get_estimated_bw() divides by link->dpia_bw_alloc_config.bw_granularity, which is zeroed by reset_bw_alloc_struct() and only populated once DP_TUNNELING_BW_ALLOC_CAP_CHANGED has been handled. link_dp_dpia_handle_bw_alloc_status(), the DPCD interrupt handler, calls get_estimated_bw() whenever DP_TUNNELING_ESTIMATED_BW_CHANGED is set, independently of whether DP_TUNNELING_BW_ALLOC_CAP_CHANGED has ever fired for that link. A connected USB4/DPIA tunneling device that reports an estimated-bandwidth change before ever reporting a capability change drives a division by zero in this IRQ path. link_dpia_send_bw_alloc_request() already guards the same bw_granularity division; add the identical guard here rather than introducing a new pattern. (cherry picked from commit f2a961457c33dc34223aad5c9e8971de34a4eed3)
Title drm/amd/display: fix division by zero in get_estimated_bw()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:33:35.281Z

Reserved: 2026-09-11T19:38:34.782Z

Link: CVE-2026-90035

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:16.690

Modified: 2026-09-16T11:17:16.690

Link: CVE-2026-90035

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:30:03Z

Weaknesses