cbcvebase.
CVE-2024-39475
published 2024-07-05

CVE-2024-39475: In the Linux kernel, the following vulnerability has been resolved: fbdev: savage: Handle err return when savagefb_check_var failed The commit…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.9th percentile
In the Linux kernel, the following vulnerability has been resolved: fbdev: savage: Handle err return when savagefb_check_var failed The commit 04e5eac8f3ab("fbdev: savage: Error out if pixclock equals zero") checks the value of pixclock to avoid divide-by-zero error. However the function savagefb_probe doesn't handle the error return of savagefb_check_var. When pixclock is 0, it will cause divide-by-zero error.

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 04e5eac8f3ab2ff52fa191c187a46d4fdbc1e288 < 5f446859bfa46df0ffb34149499f48a2c2d8cd955f446859bfa46df0ffb34149499f48a2c2d8cd95
linuxlinux>= 04e5eac8f3ab2ff52fa191c187a46d4fdbc1e288 < 6ad959b6703e2c4c5d7af03b4cfd5ff6080363396ad959b6703e2c4c5d7af03b4cfd5ff608036339
linuxlinux>= 070398d32c5f3ab0e890374904ad94551c76aec4 < edaa57480b876e8203b51df7c3d14a51ea6b09e3edaa57480b876e8203b51df7c3d14a51ea6b09e3
linuxlinux>= 224453de8505aede1890f007be973925a3edf6a1 < be754cbd77eaf2932408a4e18532e4945274a5c7be754cbd77eaf2932408a4e18532e4945274a5c7
linuxlinux>= 4.19.308 < 4.19.3164.19.316
linuxlinux>= 5.10.211 < 5.10.2195.10.219
linuxlinux>= 5.15.150 < 5.15.1615.15.161
linuxlinux>= 5.4.270 < 5.4.2785.4.278
linuxlinux>= 512ee6d6041e007ef5bf200c6e388e172a2c5b24 < 32f92b0078ebf79dbe4827288e0acb50d89d3d5b32f92b0078ebf79dbe4827288e0acb50d89d3d5b
linuxlinux>= 6.1.80 < 6.1.946.1.94
linuxlinux>= 6.6.19 < 6.6.346.6.34
linuxlinux>= 6.7.7 < 6.86.8
linuxlinux>= 84dce0f6a4cc5b7bfd7242ef9290db8ac1dd77ff < 86435f39c18967cdd937d7a49ba539cdea7fb54786435f39c18967cdd937d7a49ba539cdea7fb547
linuxlinux>= 8c54acf33e5adaad6374bf3ec1e3aff0591cc8e1 < 4b2c67e30b4e1d2ae19dba8b8e8f3b5fd3cf80894b2c67e30b4e1d2ae19dba8b8e8f3b5fd3cf8089
linuxlinux>= bc3c2e58d73b28b9a8789fca84778ee165a72d13 < b8385ff814ca4cb7e63789841e6ec2a14c73e1e8b8385ff814ca4cb7e63789841e6ec2a14c73e1e8
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-192.2125.4.0-192.212
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.