SB2026041408 - Division by zero in Linux kernel sched
Published: April 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Division by zero (CVE-ID: CVE-2026-31423)
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a divide-by-zero error in rtsc_min() in the HFSC scheduler when processing crafted traffic control parameters. A local user can supply values that make the truncated divisor become zero to cause a denial of service.
The issue is triggered in the concave-curve intersection path.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/17c1b9807b8a67d676b6dcf749ee932ebaa7f568
- https://git.kernel.org/stable/c/25b6821884713a31e2b49fb67b0ebd765b33e0a9
- https://git.kernel.org/stable/c/4576100b8cd03118267513cafacde164b498b322
- https://git.kernel.org/stable/c/b9e6431cbea8bb1fae8069ed099b4ee100499835
- https://git.kernel.org/stable/c/c56f78614e7781aaceca9bd3cb2128bf7d45c3bd
- https://git.kernel.org/stable/c/d0aefec1b1a1ba2c1d251028dc2c4e5b4ce1fea5