Back to overview

CVE-2026-64236

Description
In the Linux kernel, the following vulnerability has been resolved: i2c: davinci: fix division by zero on missing clock-frequency When the 'clock-frequency' property is missing from the device tree, the driver falls back to DAVINCI_I2C_DEFAULT_BUS_FREQ. However, this macro was defined in kHz (100), whereas the device tree property is expected in Hz. The probe function divided the fallback value by 1000, causing integer truncation that resulted in dev->bus_freq = 0. This triggered a deterministic division-by-zero kernel panic when calculating clock dividers later in the probe sequence. Fix this by redefining DAVINCI_I2C_DEFAULT_BUS_FREQ in Hz (100000) to match the expected device tree property unit, allowing the existing division logic to work correctly for both cases.

Metadata

CVE ID
CVE-2026-64236
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 15:36 UTC
Published
2026-07-24 15:27 UTC
Last updated
2026-07-24 15:27 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux b04ce63859793e3439b394976b8d29e785d4d69a < 3f43865cb64dd7cb50efae1281a95585617b12a1, b04ce63859793e3439b394976b8d29e785d4d69a < 9b694bc0e1831cbc5c3bbfd1b156ec719128f7d9, b04ce63859793e3439b394976b8d29e785d4d69a < 030675aa54cf757769b3db65642433d626b3ed7c
Linux Linux 6.14, 0 < 6.14, 6.18.35 ≤ 6.18.*, 7.0.12 ≤ 7.0.* …
Back to overview