#VU91378 Division by zero in Linux kernel


Published: 2024-06-08

Vulnerability identifier: #VU91378

Vulnerability risk: Low

CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-26778

CWE-ID: CWE-369

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a division by zero error within the savagefb_check_var() function in drivers/video/fbdev/savage/savagefb_driver.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/224453de8505aede1890f007be973925a3edf6a1
http://git.kernel.org/stable/c/84dce0f6a4cc5b7bfd7242ef9290db8ac1dd77ff
http://git.kernel.org/stable/c/512ee6d6041e007ef5bf200c6e388e172a2c5b24
http://git.kernel.org/stable/c/8c54acf33e5adaad6374bf3ec1e3aff0591cc8e1
http://git.kernel.org/stable/c/070398d32c5f3ab0e890374904ad94551c76aec4
http://git.kernel.org/stable/c/bc3c2e58d73b28b9a8789fca84778ee165a72d13
http://git.kernel.org/stable/c/a9ca4e80d23474f90841251f4ac0d941fa337a01
http://git.kernel.org/stable/c/04e5eac8f3ab2ff52fa191c187a46d4fdbc1e288


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability