CVE-2022-49978
published 2025-06-18CVE-2022-49978: In the Linux kernel, the following vulnerability has been resolved: fbdev: fb_pm2fb: Avoid potential divide by zero error In `do_fb_ioctl()` of fbmem.c, if cmd…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
fbdev: fb_pm2fb: Avoid potential divide by zero error
In `do_fb_ioctl()` of fbmem.c, if cmd is FBIOPUT_VSCREENINFO, var will be
copied from user, then go through `fb_set_var()` and
`info->fbops->fb_check_var()` which could may be `pm2fb_check_var()`.
Along the path, `var->pixclock` won't be modified. This function checks
whether reciprocal of `var->pixclock` is too high. If `var->pixclock` is
zero, there will be a divide by zero error. So, it is necessary to check
whether denominator is zero to avoid crash. As this bug is found by
Syzkaller, logs are listed below.
divide error in pm2fb_check_var
Call Trace:
fb_set_var+0x367/0xeb0 drivers/video/fbdev/core/fbmem.c:1015
do_fb_ioctl+0x234/0x670 drivers/video/fbdev/core/fbmem.c:1110
fb_ioctl+0xdd/0x130 drivers/video/fbdev/core/fbmem.c:1189
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.2-1 (bookworm) | linux 6.0.2-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 0f1174f4972ea9fad6becf8881d71adca8e9ca91 | 0f1174f4972ea9fad6becf8881d71adca8e9ca91 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3ec326a6a0d4667585ca595f438c7293e5ced7c4 | 3ec326a6a0d4667585ca595f438c7293e5ced7c4 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7f88cdfea8d7f4dbaf423d808241403b2bb945e4 | 7f88cdfea8d7f4dbaf423d808241403b2bb945e4 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7d9591b32a9092fc6391a316b56e8016c6181c3d | 7d9591b32a9092fc6391a316b56e8016c6181c3d |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8fc778ee2fb2853f7a3531fa7273349640d8e4e9 | 8fc778ee2fb2853f7a3531fa7273349640d8e4e9 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 34c3dea1189525cd533071ed5c176fc4ea8d982b | 34c3dea1189525cd533071ed5c176fc4ea8d982b |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < cb4bb011a683532841344ca7f281b5e04389b4f8 | cb4bb011a683532841344ca7f281b5e04389b4f8 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 19f953e7435644b81332dd632ba1b2d80b1e37af | 19f953e7435644b81332dd632ba1b2d80b1e37af |
| linux | linux_kernel | < 4.9.327 | 4.9.327 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.148-1 | 5.10.148-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 4.10 < 4.14.292 | 4.14.292 |
| linux | linux_kernel | >= 4.15 < 4.19.257 | 4.19.257 |
| linux | linux_kernel | >= 4.20 < 5.4.212 | 5.4.212 |
| linux | linux_kernel | >= 5.11 < 5.15.65 | 5.15.65 |
| linux | linux_kernel | >= 5.16 < 5.19.7 | 5.19.7 |
| linux | linux_kernel | >= 5.5 < 5.10.141 | 5.10.141 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: fbdev: fb_pm2fb: Avoid potential divide by zero error
vendor_redhat·2025-06-18·CVSS 5.5
CVE-2022-49978 [MEDIUM] kernel: fbdev: fb_pm2fb: Avoid potential divide by zero error
kernel: fbdev: fb_pm2fb: Avoid potential divide by zero error
In the Linux kernel, the following vulnerability has been resolved:
fbdev: fb_pm2fb: Avoid potential divide by zero error
In `do_fb_ioctl()` of fbmem.c, if cmd is FBIOPUT_VSCREENINFO, var will be
copied from user, then go through `fb_set_var()` and
`info->fbops->fb_check_var()` which could may be `pm2fb_check_var()`.
Along the path, `var->pixclock` won't be modified. This function checks
whether reciprocal of `var->pixclock` is too high. If `var->pixclock` is
zero, there will be a divide by zero error. So, it is necessary to check
whether denominator is zero to avoid crash. As this bug is found by
Syzkaller, logs are listed below.
divide error in pm2fb_check_var
Call Trace:
fb_set_var+0x367/0xeb0 drivers/video/fbdev/core/fbmem
Debian
CVE-2022-49978: linux - In the Linux kernel, the following vulnerability has been resolved: fbdev: fb_p...
vendor_debian·2022·CVSS 5.5
CVE-2022-49978 [MEDIUM] CVE-2022-49978: linux - In the Linux kernel, the following vulnerability has been resolved: fbdev: fb_p...
In the Linux kernel, the following vulnerability has been resolved: fbdev: fb_pm2fb: Avoid potential divide by zero error In `do_fb_ioctl()` of fbmem.c, if cmd is FBIOPUT_VSCREENINFO, var will be copied from user, then go through `fb_set_var()` and `info->fbops->fb_check_var()` which could may be `pm2fb_check_var()`. Along the path, `var->pixclock` won't be modified. This function checks whether reciprocal of `var->pixclock` is too high. If `var->pixclock` is zero, there will be a divide by zero error. So, it is necessary to check whether denominator is zero to avoid crash. As this bug is found by Syzkaller, logs are listed below. divide error in pm2fb_check_var Call Trace: fb_set_var+0x367/0xeb0 drivers/video/fbdev/core/fbmem.c:1015 do_fb_ioctl+0x234/0x670 drivers/video/fbdev/core/fbmem.c
OSV
CVE-2022-49978: In the Linux kernel, the following vulnerability has been resolved: fbdev: fb_pm2fb: Avoid potential divide by zero error In `do_fb_ioctl()` of fbmem
osv·2025-06-18·CVSS 5.5
CVE-2022-49978 [MEDIUM] CVE-2022-49978: In the Linux kernel, the following vulnerability has been resolved: fbdev: fb_pm2fb: Avoid potential divide by zero error In `do_fb_ioctl()` of fbmem
In the Linux kernel, the following vulnerability has been resolved: fbdev: fb_pm2fb: Avoid potential divide by zero error In `do_fb_ioctl()` of fbmem.c, if cmd is FBIOPUT_VSCREENINFO, var will be copied from user, then go through `fb_set_var()` and `info->fbops->fb_check_var()` which could may be `pm2fb_check_var()`. Along the path, `var->pixclock` won't be modified. This function checks whether reciprocal of `var->pixclock` is too high. If `var->pixclock` is zero, there will be a divide by zero error. So, it is necessary to check whether denominator is zero to avoid crash. As this bug is found by Syzkaller, logs are listed below. divide error in pm2fb_check_var Call Trace: fb_set_var+0x367/0xeb0 drivers/video/fbdev/core/fbmem.c:1015 do_fb_ioctl+0x234/0x670 drivers/video/fbdev/core/fbmem.c
GHSA
GHSA-2p5r-q4hr-3fg4: In the Linux kernel, the following vulnerability has been resolved:
fbdev: fb_pm2fb: Avoid potential divide by zero error
In `do_fb_ioctl()` of fbme
ghsa_unreviewed·2025-06-18
CVE-2022-49978 [MEDIUM] CWE-369 GHSA-2p5r-q4hr-3fg4: In the Linux kernel, the following vulnerability has been resolved:
fbdev: fb_pm2fb: Avoid potential divide by zero error
In `do_fb_ioctl()` of fbme
In the Linux kernel, the following vulnerability has been resolved:
fbdev: fb_pm2fb: Avoid potential divide by zero error
In `do_fb_ioctl()` of fbmem.c, if cmd is FBIOPUT_VSCREENINFO, var will be
copied from user, then go through `fb_set_var()` and
`info->fbops->fb_check_var()` which could may be `pm2fb_check_var()`.
Along the path, `var->pixclock` won't be modified. This function checks
whether reciprocal of `var->pixclock` is too high. If `var->pixclock` is
zero, there will be a divide by zero error. So, it is necessary to check
whether denominator is zero to avoid crash. As this bug is found by
Syzkaller, logs are listed below.
divide error in pm2fb_check_var
Call Trace:
fb_set_var+0x367/0xeb0 drivers/video/fbdev/core/fbmem.c:1015
do_fb_ioctl+0x234/0x670 drivers/video/fbdev/core/fbm
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0f1174f4972ea9fad6becf8881d71adca8e9ca91https://git.kernel.org/stable/c/19f953e7435644b81332dd632ba1b2d80b1e37afhttps://git.kernel.org/stable/c/34c3dea1189525cd533071ed5c176fc4ea8d982bhttps://git.kernel.org/stable/c/3ec326a6a0d4667585ca595f438c7293e5ced7c4https://git.kernel.org/stable/c/7d9591b32a9092fc6391a316b56e8016c6181c3dhttps://git.kernel.org/stable/c/7f88cdfea8d7f4dbaf423d808241403b2bb945e4https://git.kernel.org/stable/c/8fc778ee2fb2853f7a3531fa7273349640d8e4e9https://git.kernel.org/stable/c/cb4bb011a683532841344ca7f281b5e04389b4f8
2025-06-18
Published