CVE-2026-31605: fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO
Published Apr 24, 2026
·Updated
fbdev: udlfb: avoid divide-by-zero on FBIOPUTVSCREENINFO
Affected Software
7 affected componentsFixes available
Linux Foundation Linux kernel (udlfb fbdev driver)
Linux Linux kernel>=2.6.34<6.6.136
Linux Linux kernel>=6.7<6.12.83
Linux Linux kernel>=6.13<6.18.24
Linux Linux kernel>=6.19<6.19.14
Linux Linux kernel>=7.0<7.0.1
Microsoft azl3 kernel 6.6.134.1-2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Until a kernel containing the udlfb fix is deployed, mitigate risk by unloading or blacklisting the udlfb framebuffer driver (udlfb) on affected systems or otherwise preventing use of the FBIOPUT_VSCREENINFO ioctl to avoid the divide-by-zero crash.
Event History
Apr 24, 2026
CVE Published
via MITRE·02:42 PM
Data Sourced
via MITRE·02:42 PM
Description
Data Sourced
via NVD·03:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 26, 2026
Data Sourced
via Microsoft·08:03 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:03 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-31605?
CVE-2026-31605 has a medium severity rating with a CVSS score of 5.5.
2
What type of vulnerability is identified by CVE-2026-31605?
CVE-2026-31605 is classified as a Divide by Zero vulnerability.
3
How do I fix CVE-2026-31605?
To fix CVE-2026-31605, apply the available patches provided by the Linux kernel developers.
4
Which software is affected by CVE-2026-31605?
CVE-2026-31605 affects the Linux kernel, specifically the udlfb fbdev driver.
5
When was CVE-2026-31605 published?
CVE-2026-31605 was published on April 24, 2026.