cbcvebase.
CVE-2024-36969
published 2024-06-08

CVE-2024-36969: In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix division by zero in setup_dsc_config When slice_height is 0, the…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.7th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix division by zero in setup_dsc_config When slice_height is 0, the division by slice_height in the calculation of the number of slices will cause a division by zero driver crash. This leaves the kernel in a state that requires a reboot. This patch adds a check to avoid the division by zero. The stack trace below is for the 6.8.4 Kernel. I reproduced the issue on a Z16 Gen 2 Lenovo Thinkpad with a Apple Studio Display monitor connected via Thunderbolt. The amdgpu driver crashed with this exception when I rebooted the system with the monitor connected. kernel: ? die (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:434 arch/x86/kernel/dumpstack.c:447) kernel: ? do_trap (arch/x86/kernel/traps.c:113 arch/x86/kernel/traps.c:154) kernel: ? setup_dsc_config (drivers/gpu/drm/amd/amdgpu/../display/dc/dsc/dc_dsc.c:1053) amdgpu kernel: ? do_error_trap (./arch/x86/include/asm/traps.h:58 arch/x86/kernel/traps.c:175) kernel: ? setup_dsc_config (drivers/gpu/drm/amd/amdgpu/../display/dc/dsc/dc_dsc.c:1053) amdgpu kernel: ? exc_divide_error (arch/x86/kernel/traps.c:194 (discriminator 2)) kernel: ? setup_dsc_config (drivers/gpu/drm/amd/amdgpu/../display/dc/dsc/dc_dsc.c:1053) amdgpu kernel: ? asm_exc_divide_error (./arch/x86/include/asm/idtentry.h:548) kernel: ? setup_dsc_config (drivers/gpu/drm/amd/amdgpu/../display/dc/dsc/dc_dsc.c:1053) amdgpu kernel: dc_dsc_compute_config (drivers/gpu/drm/amd/amdgpu/../display/dc/dsc/dc_dsc.c:1109) amdgpu After applying this patch, the driver no longer crashes when the monitor is connected and the system is rebooted. I believe this is the same issue reported for 3113.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < a32c8f951c8a456c1c251e1dcdf21787f8066445a32c8f951c8a456c1c251e1dcdf21787f8066445
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 91402e0e5de9124a3108db7a14163fcf9a6d322f91402e0e5de9124a3108db7a14163fcf9a6d322f
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 7e4f50dfc98c49b3dc6875a35c3112522fb256397e4f50dfc98c49b3dc6875a35c3112522fb25639
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < f187fcbbb8f8bf10c6687f0beae22509369f7563f187fcbbb8f8bf10c6687f0beae22509369f7563
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 308de6be0c9c7ba36915c0d398e771725c0ea911308de6be0c9c7ba36915c0d398e771725c0ea911
linuxlinux>= 4562236b3bc0a28aeb6ee93b2d8a849a4c4e1c7c < 130afc8a886183a94cf6eab7d24f300014ff87ba130afc8a886183a94cf6eab7d24f300014ff87ba
linuxlinux_kernel< 5.15.1605.15.160
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 5.15.0-118.1285.15.0-118.128
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 5.16 < 6.1.926.1.92
linuxlinux_kernel>= 6.2 < 6.6.326.6.32
linuxlinux_kernel>= 6.7 < 6.8.116.8.11
linuxlinux_kernel>= 6.9 < 6.9.26.9.2
msrcazl3_kernel_6.6.22.1-2_on_azure_linux_3.0
msrcazl3_kernel_6.6.35.1-5_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.