CVE-2026-68356: watchdog: airoha: Prevent division by zero when clock frequency is zero
In the Linux kernel, the following vulnerability has been resolved:
watchdog: airoha: Prevent division by zero when clock frequency is zero
clkgetrate() can return 0 when the clock provider is not properly configured or the clock is unmanaged. The driver uses wdtfreq as a divisor directly in airohawdtprobe() to compute maxtimeout and in airohawdtgettimeleft() to compute the remaining time, which results in a division by zero.
Add a check for wdtfreq == 0 in probe and return -EINVAL with deverrprobe() to prevent the division by zero and provide a diagnostic message.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
In airoha_wdt_probe()/probe, add a check: if wdt_freq == 0, use dev_err_probe() to emit a diagnostic message and return -EINVAL to prevent division by zero when computing max_timeout.
Linux kernel driver watchdog: airoha wdt_freq = must be non-zero
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68356?
CVE-2026-68356 has a risk rating of 12.
How do I fix CVE-2026-68356?
To fix CVE-2026-68356, ensure that the clock provider is properly configured to prevent clk_get_rate() returning zero.
What systems are affected by CVE-2026-68356?
CVE-2026-68356 affects the Linux Kernel, specifically the airoha watchdog driver.
What exploit does CVE-2026-68356 mitigate?
CVE-2026-68356 mitigates the risk of division by zero errors in the airoha watchdog driver.
When was CVE-2026-68356 published?
CVE-2026-68356 was published on August 10, 2026.