CVE-2026-64236 is a vulnerability in Linux Kernel
Published on July 24, 2026
i2c: davinci: fix division by zero on missing clock-frequency
In the Linux kernel, the following vulnerability has been resolved:
i2c: davinci: fix division by zero on missing clock-frequency
When the 'clock-frequency' property is missing from the device tree,
the driver falls back to DAVINCI_I2C_DEFAULT_BUS_FREQ. However, this
macro was defined in kHz (100), whereas the device tree property is
expected in Hz.
The probe function divided the fallback value by 1000, causing
integer truncation that resulted in dev->bus_freq = 0. This triggered
a deterministic division-by-zero kernel panic when calculating clock
dividers later in the probe sequence.
Fix this by redefining DAVINCI_I2C_DEFAULT_BUS_FREQ in Hz (100000)
to match the expected device tree property unit, allowing the existing
division logic to work correctly for both cases.
Products Associated with CVE-2026-64236
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version b04ce63859793e3439b394976b8d29e785d4d69a and below 3f43865cb64dd7cb50efae1281a95585617b12a1 is affected.
- Version b04ce63859793e3439b394976b8d29e785d4d69a and below 9b694bc0e1831cbc5c3bbfd1b156ec719128f7d9 is affected.
- Version b04ce63859793e3439b394976b8d29e785d4d69a and below 030675aa54cf757769b3db65642433d626b3ed7c is affected.
- Version 6.14 is affected.
- Before 6.14 is unaffected.
- Version 6.18.35, <= 6.18.* is unaffected.
- Version 7.0.12, <= 7.0.* is unaffected.
- Version 7.1, <= * is unaffected.