In the Linux kernel, the following vulnerability has been resolved:
fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod()
In fb_find_mode_cvt(), iff mode->refresh somehow happens to be 0x80000000,
cvt.f_refresh will become 0 when multiplying it by 2 due to overflow. It's
then passed to fb_cvt_hperiod(), where it's used as a divider -- division
by 0 will result in kernel oops. Add a sanity check for cvt.f_refresh to
avoid such overflow...
Found by Linux Verification Center (linuxtesting.org) with the Svace static
analysis tool.
Metrics
Affected Vendors & Products
References
History
Thu, 10 Jul 2025 08:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In the Linux kernel, the following vulnerability has been resolved: fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod() In fb_find_mode_cvt(), iff mode->refresh somehow happens to be 0x80000000, cvt.f_refresh will become 0 when multiplying it by 2 due to overflow. It's then passed to fb_cvt_hperiod(), where it's used as a divider -- division by 0 will result in kernel oops. Add a sanity check for cvt.f_refresh to avoid such overflow... Found by Linux Verification Center (linuxtesting.org) with the Svace static analysis tool. | |
Title | fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod() | |
References |
|
|

Status: PUBLISHED
Assigner: Linux
Published: 2025-07-10T07:42:20.647Z
Updated: 2025-07-10T07:42:20.647Z
Reserved: 2025-04-16T04:51:24.003Z
Link: CVE-2025-38312

No data.

Status : Awaiting Analysis
Published: 2025-07-10T08:15:30.120
Modified: 2025-07-10T13:17:30.017
Link: CVE-2025-38312

No data.