{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89806","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.767Z","datePublished":"2026-09-16T10:30:39.548Z","dateUpdated":"2026-10-03T10:56:42.335Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:56:42.335Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/sysfb: ofdrm: Fix integer overflow in fb_size calculation\n\nThe framebuffer size calculation `fb_size = linebytes * height` can\noverflow when both values are large (e.g., 46341 * 46341 > INT_MAX).\nSince linebytes and height are both int types, the multiplication is\nperformed as int * int, which results in undefined behavior on overflow.\n\nUse check_mul_overflow() to detect and prevent this overflow, consistent\nwith the approach used in simpledrm.c and corebootdrm.c."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The overflow is in ofdrm_device_create() on the local platform probe path (ofdrm_probe matching Open Firmware compatible=display); it is not reached from network protocols, Bluetooth, USB, or other remote packet handlers.\nAC:L - An attacker who supplies OF width/linebytes/height (e.g. 46341x46341) deterministically overflows the int multiply fb_size=linebytes*height; there is no race, layout luck, or other condition outside attacker control.\nPR:N - ofdrm_probe runs automatically from the platform bus with no capability check; a crafted display node can be supplied without an OS account via netboot/PXE, QEMU/hypervisor Open Firmware, or firmware, so no privileges on the running system are required.\nUI:N - Once a malicious display node is present, framebuffer size is computed during unattended driver probe; no victim mount, file open, or other interactive action is required.\nS:U - The overflow and resulting framebuffer mapping errors affect kernel and MMIO state on the same host; this is a standard in-kernel driver defect, not a VM escape, IOMMU bypass, or other cross-authority impact.\nC:H - A wrapped fb_size ioremaps a too-small aperture while scanout still uses the attacker-chosen pitch and height, enabling out-of-bounds reads of adjacent ioremap/vmalloc memory; memory-corruption OOB access is High confidentiality.\nI:H - The undersized mapping causes out-of-bounds writes through drm_sysfb blit/disable paths and DRM/fbdev clients past the mapped firmware framebuffer, which is an OOB write scored as High integrity impact.\nA:H - Accesses past the ioremap'd region cause kernel page-fault oops or panic during probe-time DRM client setup or later modeset/blit, fully denying availability on affected Open Firmware display systems."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/sysfb/ofdrm.c"],"versions":[{"version":"c8a17756c42581ba1a567d1dd3b69e8f5619a7d8","lessThan":"711fe7949d37656a5586244afee9523b9e5e37e9","status":"affected","versionType":"git"},{"version":"c8a17756c42581ba1a567d1dd3b69e8f5619a7d8","lessThan":"ded6ad826fe0fd059333d3a3b3e1742c8e45ff41","status":"affected","versionType":"git"},{"version":"c8a17756c42581ba1a567d1dd3b69e8f5619a7d8","lessThan":"d9daf9a6e7a6f82ef338a09386eefc6807100d3f","status":"affected","versionType":"git"},{"version":"c8a17756c42581ba1a567d1dd3b69e8f5619a7d8","lessThan":"c6f48e59ece0123f6a11527ad4d89b21c2d65b87","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/sysfb/ofdrm.c"],"versions":[{"version":"6.2","status":"affected"},{"version":"0","lessThan":"6.2","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"7.3-rc2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/711fe7949d37656a5586244afee9523b9e5e37e9"},{"url":"https://git.kernel.org/stable/c/ded6ad826fe0fd059333d3a3b3e1742c8e45ff41"},{"url":"https://git.kernel.org/stable/c/d9daf9a6e7a6f82ef338a09386eefc6807100d3f"},{"url":"https://git.kernel.org/stable/c/c6f48e59ece0123f6a11527ad4d89b21c2d65b87"}],"title":"drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation","x_generator":{"engine":"bippy-1.2.0"}}}}