Description
In the Linux kernel, the following vulnerability has been resolved:

fbdev: kyro: Validate overlay viewport coordinates

The overlay viewport end coordinates are computed from the viewport
origin and dimensions using 32-bit unsigned arithmetic. Large input
values can cause these calculations to wrap around before the resulting
coordinates are passed to SetOverlayViewPort().

SetOverlayViewPort() packs the viewport coordinates into 16-bit
register fields. The X coordinates are additionally adjusted by +2
and +1 before being written. Validate the coordinate calculations
for 32-bit wraparound and ensure that the adjusted coordinates fit
within their 16-bit register fields before calling
SetOverlayViewPort().

Found by Linux Verification Center (linuxtesting.org) with SVACE.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption via integer overflow
Action: Patch Now
AI Analysis

Impact

The kyro overlay driver in the Linux kernel performs viewport coordinate calculations using 32‑bit unsigned arithmetic. When large input values are supplied, the intermediate calculations wrap around before the results are passed to SetOverlayViewPort(). Because the driver does not verify that the adjusted coordinates fit into the 16‑bit hardware register fields, this wraparound can cause invalid register values to be written. The resulting kernel memory corruption could lead to incorrect graphics state or potentially alter kernel execution behavior.

Affected Systems

This vulnerability affects the Linux kernel’s fbdev kyro overlay driver. All kernel versions that include the kyro driver and do not incorporate the patch that validates viewport coordinates are potentially vulnerable. No specific kernel release is listed, so any kernel using the kyro functionality is at risk until the driver is updated or disabled.

Risk and Exploitability

The EPSS score is less than 1 % and the flaw is not listed in CISA’s KEV catalog, indicating that widespread exploitation has not been observed. However, the vulnerability can be triggered by providing large viewport dimensions to the SetOverlayViewPort() call, which typically requires privileged access to the graphics subsystem. A local privileged attacker could exploit the integer wraparound to corrupt kernel memory, resulting in high potential impact on confidentiality, integrity, and availability. Given the low EPSS and lack of known exploitation, the overall risk is moderate but remediation is strongly recommended.

Generated by OpenCVE AI on September 19, 2026 at 15:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that patches the kyro overlay driver to validate viewport coordinates and enforce 16‑bit bounds before calling SetOverlayViewPort().
  • If an update is unavailable, disable the kyro overlay functionality by removing or disabling the fbdev kyro driver module or configuring the kernel to avoid using this hardware overlay feature.
  • Check the latest kernel release notes and vendor advisories on the Linux kernel project site to confirm that the fix has been deployed and upgrade accordingly.

Generated by OpenCVE AI on September 19, 2026 at 15:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: fbdev: kyro: Validate overlay viewport coordinates The overlay viewport end coordinates are computed from the viewport origin and dimensions using 32-bit unsigned arithmetic. Large input values can cause these calculations to wrap around before the resulting coordinates are passed to SetOverlayViewPort(). SetOverlayViewPort() packs the viewport coordinates into 16-bit register fields. The X coordinates are additionally adjusted by +2 and +1 before being written. Validate the coordinate calculations for 32-bit wraparound and ensure that the adjusted coordinates fit within their 16-bit register fields before calling SetOverlayViewPort(). Found by Linux Verification Center (linuxtesting.org) with SVACE.
Title fbdev: kyro: Validate overlay viewport coordinates
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:47.765Z

Reserved: 2026-09-11T19:38:34.795Z

Link: CVE-2026-90245

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:20.530

Modified: 2026-09-17T17:17:20.530

Link: CVE-2026-90245

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:15:14Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound