CVE-2026-68254

Source
https://cve.org/CVERecord?id=CVE-2026-68254
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68254.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-68254
Downstream
Published
2026-08-10T12:01:20Z
Modified
2026-08-25T03:30:10Z
Summary
drm/i915/vrr: require valid min/max vfreq for VRR
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/i915/vrr: require valid min/max vfreq for VRR

Ensure the EDID provided min/max vfreq are valid. Most scenarios are already covered (by coincidence) through the checks in intel_vrr_is_capable() and intel_vrr_is_in_range(), but be more explicit about it. At worst, a zero min_vfreq could lead to a division by zero in intel_vrr_compute_vmax().

Discovered using AI-assisted static analysis confirmed by Intel Product Security.

(cherry picked from commit 1765cf59f517b02f3b0591fe5120930d08bddeb6)

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68254.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
117cd09ba52857a60dc5d7f61941046625d8ff5a
Fixed
2f9aa8d42b7fc17621894456433ac07689fb4a21
Fixed
5225122b9cad6b0c61e767fb2adea8c07da925be
Fixed
6598ac1721c3a5543efdbcab579a8561268d7ce1
Fixed
f16218689b41efcbc491207cd7716477b1223879
Fixed
df1582c0a101e2e2f133dd331d2a3258bb6a7518
Fixed
c726c8bbee5115dad37fa7867136ebaa50690331
Fixed
f8a9262c7a6fc2de9802e14b0228114f0333869e

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68254.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.12.0
Fixed
5.15.217
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.184
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.151
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68254.json"