Vulnerability identifier: #VU96545
Vulnerability risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-369
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a division by zero error within the padata_do_multithreaded() function in kernel/padata.c. A local user can perform a denial of service (DoS) attack.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Linux kernel: All versions
External links
https://git.kernel.org/stable/c/ab8b397d5997d8c37610252528edc54bebf9f6d3
https://git.kernel.org/stable/c/8f5ffd2af7274853ff91d6cd62541191d9fbd10d
https://git.kernel.org/stable/c/a29cfcb848c31f22b4de6a531c3e1d68c9bfe09f
https://git.kernel.org/stable/c/924f788c906dccaca30acab86c7124371e1d6f2c
https://git.kernel.org/stable/c/da0ffe84fcc1627a7dff82c80b823b94236af905
https://git.kernel.org/stable/c/6d45e1c948a8b7ed6ceddb14319af69424db730c
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.