drm/i915/vrr: require valid min/max vfreq for VRR
Summary
| CVE | CVE-2026-68254 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-10 13:20:13 UTC |
| Updated | 2026-08-23 13:16:35 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: drm/i915/vrr: require valid min/max vfreq for VRR Ensure the EDID provided min/max vfreq are valid. Most scenarios are already covered (by coincidence) through the checks in intel_vrr_is_capable() and intel_vrr_is_in_range(), but be more explicit about it. At worst, a zero min_vfreq could lead to a division by zero in intel_vrr_compute_vmax(). Discovered using AI-assisted static analysis confirmed by Intel Product Security. (cherry picked from commit 1765cf59f517b02f3b0591fe5120930d08bddeb6) |
Risk And Classification
EPSS: 0.001720000 probability, percentile 0.066830000 (date 2026-08-24)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 117cd09ba52857a60dc5d7f61941046625d8ff5a 2f9aa8d42b7fc17621894456433ac07689fb4a21 git | Not specified |
| CNA | Linux | Linux | affected 117cd09ba52857a60dc5d7f61941046625d8ff5a 5225122b9cad6b0c61e767fb2adea8c07da925be git | Not specified |
| CNA | Linux | Linux | affected 117cd09ba52857a60dc5d7f61941046625d8ff5a 6598ac1721c3a5543efdbcab579a8561268d7ce1 git | Not specified |
| CNA | Linux | Linux | affected 117cd09ba52857a60dc5d7f61941046625d8ff5a f16218689b41efcbc491207cd7716477b1223879 git | Not specified |
| CNA | Linux | Linux | affected 117cd09ba52857a60dc5d7f61941046625d8ff5a df1582c0a101e2e2f133dd331d2a3258bb6a7518 git | Not specified |
| CNA | Linux | Linux | affected 117cd09ba52857a60dc5d7f61941046625d8ff5a c726c8bbee5115dad37fa7867136ebaa50690331 git | Not specified |
| CNA | Linux | Linux | affected 117cd09ba52857a60dc5d7f61941046625d8ff5a f8a9262c7a6fc2de9802e14b0228114f0333869e git | Not specified |
| CNA | Linux | Linux | affected 5.12 | Not specified |
| CNA | Linux | Linux | unaffected 5.12 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.217 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.184 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.151 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.103 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.44 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.6 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/c726c8bbee5115dad37fa7867136ebaa50690331 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/6598ac1721c3a5543efdbcab579a8561268d7ce1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/2f9aa8d42b7fc17621894456433ac07689fb4a21 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/f16218689b41efcbc491207cd7716477b1223879 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/df1582c0a101e2e2f133dd331d2a3258bb6a7518 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/5225122b9cad6b0c61e767fb2adea8c07da925be | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/f8a9262c7a6fc2de9802e14b0228114f0333869e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.