CVE-2026-72394: hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero
Sashiko reports:
In the aspeed-g6-pwm-tacho driver, the aspeedtachvaltorpm() function calculates the fan RPM using the tachometer value. However, it does not check if the tachometer value is zero before performing the division.
If the hardware reports a tachometer value of 0 (which can happen due to an extremely fast pulse, a stuck edge, or a hardware glitch), the calculated tachdiv evaluates to 0. The subsequent call to dodiv() with tachdiv as the divisor triggers a divide-by-zero exception, leading to a kernel panic.
Check the divisor against zero to fix the problem.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
In aspeed-g6-pwm-tacho, add a guard in aspeed_tach_val_to_rpm(): before calling do_div() with tach_div as the divisor, check the tachometer value; if it evaluates to 0, skip the division to prevent a divide-by-zero kernel panic.
Linux kernel (aspeed-g6-pwm-tacho driver) Guard tachometer RPM calculation against divide-by-zero = if tachometer value is 0, do not perform do_div()/division