CVE-2026-89806

Source
https://cve.org/CVERecord?id=CVE-2026-89806
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89806.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89806
Downstream
Published
2026-09-16T10:30:39Z
Modified
2026-09-18T03:48:32Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation

The framebuffer size calculation fb_size = linebytes * height can overflow when both values are large (e.g., 46341 * 46341 > INT_MAX). Since linebytes and height are both int types, the multiplication is performed as int * int, which results in undefined behavior on overflow.

Use check_mul_overflow() to detect and prevent this overflow, consistent with the approach used in simpledrm.c and corebootdrm.c.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89806.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c8a17756c42581ba1a567d1dd3b69e8f5619a7d8
Fixed
ded6ad826fe0fd059333d3a3b3e1742c8e45ff41
Fixed
d9daf9a6e7a6f82ef338a09386eefc6807100d3f
Fixed
c6f48e59ece0123f6a11527ad4d89b21c2d65b87

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89806.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89806.json"