SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-64236

MEDIUM · CVSS 5.5 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's I2C driver for Davinci devices, where a missing 'clock-frequency' property leads to a division by zero error during the probe function. This results in a kernel panic, potentially causing system instability or crashes. Linux system administrators and developers utilizing the affected I2C driver should prioritize applying the fix to prevent operational disruptions.

CVE
CVE-2026-64236
Severity
MEDIUM
CVSS
5.5
EPSS
0.11%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: i2c: davinci: fix division by zero on missing clock-frequency When the 'clock-frequency' property is missing from the device tree, the driver falls back to DAVINCI_I2C_DEFAULT_BUS_FREQ. However, this macro was defined in kHz (100), whereas the device tree property is expected in Hz. The probe function divided the fallback value by 1000, causing integer truncation that resulted in dev->bus_freq = 0. This triggered a deterministic division-by-zero kernel panic when calculating clock dividers later in the probe sequence. Fix this by redefining DAVINCI_I2C_DEFAULT_BUS_FREQ in Hz (100000) to match the expected device tree property unit, allowing the existing division logic to work correctly for both cases.

Related CVEs

Other vulnerabilities affecting the same vendor(s)