Division by Zero Vulnerability in Linux Kernel Affecting Davinci I2C Driver
CVE-2026-64236
What is CVE-2026-64236?
A vulnerability in the Linux kernel's Davinci I2C driver arises when the 'clock-frequency' property is omitted from the device tree. The driver reverts to a default bus frequency defined in kilohertz, leading to erroneous integer division which eventually results in a kernel panic due to division by zero. To address this issue, the default bus frequency value has been redefined in hertz, ensuring compatibility with the expected device tree configuration and preventing potential system instability during the probe sequence.
Affected Version(s)
Linux b04ce63859793e3439b394976b8d29e785d4d69a < 3f43865cb64dd7cb50efae1281a95585617b12a1
Linux b04ce63859793e3439b394976b8d29e785d4d69a < 9b694bc0e1831cbc5c3bbfd1b156ec719128f7d9
Linux b04ce63859793e3439b394976b8d29e785d4d69a < 030675aa54cf757769b3db65642433d626b3ed7c