CVE-2026-90245
In the Linux kernel, the following vulnerability has been resolved:
fbdev: kyro: Validate overlay viewport coordinates
The overlay viewport end coordinates are computed from the viewport origin and dimensions using 32-bit unsigned arithmetic. Large input values can cause these calculations to wrap around before the resulting coordinates are passed to SetOverlayViewPort().
SetOverlayViewPort() packs the viewport coordinates into 16-bit register fields. The X coordinates are additionally adjusted by +2 and +1 before being written. Validate the coordinate calculations for 32-bit wraparound and ensure that the adjusted coordinates fit within their 16-bit register fields before calling SetOverlayViewPort().
Leer descripción completaMostrar menos
Found by Linux Verification Center (linuxtesting.org) with SVACE.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/2ac6e30a552e6f9932c21c865a5c69f40c8aef64
- https://git.kernel.org/stable/c/33e54e3e0b2ca959304e62c3d84f0ad49bbe1afe
- https://git.kernel.org/stable/c/413d763439ba68e5d547538e6b6c7de97d5818a5
- https://git.kernel.org/stable/c/7b5c7bc55e13e7f5ac7b1eaf5c6d690389ea5ee3
- https://git.kernel.org/stable/c/7bf36dc23bcf3496dec274a46ae0aaff4961ea03
- https://git.kernel.org/stable/c/a6decd4e72fc5846d3b268bd085a2089213fd5ee
- https://git.kernel.org/stable/c/d8c1a9579cbd8f4ac5cbd5a10f1afb5ee64adf30
- https://git.kernel.org/stable/c/e8d4e4cf388daeb49704f3de10b203034f28eb90
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90245",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "d8c1a9579cbd8f4ac5cbd5a10f1afb5ee64adf30",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "2ac6e30a552e6f9932c21c865a5c69f40c8aef64",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "413d763439ba68e5d547538e6b6c7de97d5818a5",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "e8d4e4cf388daeb49704f3de10b203034f28eb90",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "a6decd4e72fc5846d3b268bd085a2089213fd5ee",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "33e54e3e0b2ca959304e62c3d84f0ad49bbe1afe",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "7bf36dc23bcf3496dec274a46ae0aaff4961ea03",
"versionType": "git"
},
{
"status": "affected",
"version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
"lessThan": "7b5c7bc55e13e7f5ac7b1eaf5c6d690389ea5ee3",
"versionType": "git"
}
],
"programFiles": [
"drivers/video/fbdev/kyro/fbdev.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.12"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.12",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.270",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.221",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/video/fbdev/kyro/fbdev.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:17:20.530",
"references": [
{
"url": "https://git.kernel.org/stable/c/2ac6e30a552e6f9932c21c865a5c69f40c8aef64",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/33e54e3e0b2ca959304e62c3d84f0ad49bbe1afe",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/413d763439ba68e5d547538e6b6c7de97d5818a5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7b5c7bc55e13e7f5ac7b1eaf5c6d690389ea5ee3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7bf36dc23bcf3496dec274a46ae0aaff4961ea03",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a6decd4e72fc5846d3b268bd085a2089213fd5ee",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d8c1a9579cbd8f4ac5cbd5a10f1afb5ee64adf30",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e8d4e4cf388daeb49704f3de10b203034f28eb90",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: kyro: Validate overlay viewport coordinates\n\nThe overlay viewport end coordinates are computed from the viewport\norigin and dimensions using 32-bit unsigned arithmetic. Large input\nvalues can cause these calculations to wrap around before the resulting\ncoordinates are passed to SetOverlayViewPort().\n\nSetOverlayViewPort() packs the viewport coordinates into 16-bit\nregister fields. The X coordinates are additionally adjusted by +2\nand +1 before being written. Validate the coordinate calculations\nfor 32-bit wraparound and ensure that the adjusted coordinates fit\nwithin their 16-bit register fields before calling\nSetOverlayViewPort().\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE."
}
],
"lastModified": "2026-09-17T17:17:20.530",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}