CVE-2022-3061Divide By Zero in Linux

CWE-369Divide By Zero40 documents7 sources
Severity
5.5MEDIUMNVD
OSV8.8OSV7.8OSV5.9OSV4.4
EPSS
0.0%
top 93.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 1
Latest updateApr 3

Description

Found Linux Kernel flaw in the i740 driver. The Userspace program could pass any values to the driver through ioctl() interface. The driver doesn't check the value of 'pixclock', so it may cause a divide by zero error.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDlinux/linux_kernel4.205.4.270+8
Debianlinux/linux_kernel< 5.10.216-1+7
Ubuntulinux/linux_kernel< 4.15.0-201.212+3
CVEListV5linux/linux1da177e4c3f41524e886b7f1b8a0c1fc7321cac2224453de8505aede1890f007be973925a3edf6a1+8
debiandebian/linux< linux 5.18.2-1 (bookworm)+1

Also affects: Debian Linux 10.0, 11.0

Patches

🔴Vulnerability Details

19
GHSA
GHSA-4m6c-v88j-qqxh: In the Linux kernel, the following vulnerability has been resolved: fbdev: savage: Error out if pixclock equals zero The userspace program could pas2024-04-03
OSV
CVE-2024-26778: In the Linux kernel, the following vulnerability has been resolved: fbdev: savage: Error out if pixclock equals zero The userspace program could pass2024-04-03
OSV
CVE-2024-26777: In the Linux kernel, the following vulnerability has been resolved: fbdev: sis: Error out if pixclock equals zero The userspace program could pass any2024-04-03
GHSA
GHSA-7mjh-m8r7-cjw8: In the Linux kernel, the following vulnerability has been resolved: fbdev: sis: Error out if pixclock equals zero The userspace program could pass a2024-04-03
Kernel
fbdev: savage: Error out if pixclock equals zero2024-01-18

📋Vendor Advisories

18
Red Hat
kernel: fbdev: sis: Error out if pixclock equals zero2024-04-03
Red Hat
kernel: fbdev: savage: Error out if pixclock equals zero2024-04-03
Debian
CVE-2024-26777: linux - In the Linux kernel, the following vulnerability has been resolved: fbdev: sis:...2024
Debian
CVE-2024-26778: linux - In the Linux kernel, the following vulnerability has been resolved: fbdev: sava...2024
Ubuntu
Linux kernel (AWS) vulnerabilities2023-04-12