cbcvebase.
CVE-2024-43889
published 2024-08-26

CVE-2024-43889: In the Linux kernel, the following vulnerability has been resolved: padata: Fix possible divide-by-0 panic in padata_mt_helper() We are hit with a not easily…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.8th percentile
In the Linux kernel, the following vulnerability has been resolved: padata: Fix possible divide-by-0 panic in padata_mt_helper() We are hit with a not easily reproducible divide-by-0 panic in padata.c at bootup time. [ 10.017908] Oops: divide error: 0000 1 PREEMPT SMP NOPTI [ 10.017908] CPU: 26 PID: 2627 Comm: kworker/u1666:1 Not tainted 6.10.0-15.el10.x86_64 #1 [ 10.017908] Hardware name: Lenovo ThinkSystem SR950 [7X12CTO1WW]/[7X12CTO1WW], BIOS [PSE140J-2.30] 07/20/2021 [ 10.017908] Workqueue: events_unbound padata_mt_helper [ 10.017908] RIP: 0010:padata_mt_helper+0x39/0xb0 : [ 10.017963] Call Trace: [ 10.017968] [ 10.018004] ? padata_mt_helper+0x39/0xb0 [ 10.018084] process_one_work+0x174/0x330 [ 10.018093] worker_thread+0x266/0x3a0 [ 10.018111] kthread+0xcf/0x100 [ 10.018124] ret_from_fork+0x31/0x50 [ 10.018138] ret_from_fork_asm+0x1a/0x30 [ 10.018147] Looking at the padata_mt_helper() function, the only way a divide-by-0 panic can happen is when ps->chunk_size is 0. The way that chunk_size is initialized in padata_do_multithreaded(), chunk_size can be 0 when the min_chunk in the passed-in padata_mt_job structure is 0. Fix this divide-by-0 panic by making sure that chunk_size will be at least 1 no matter what the input parameters are.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= 004ed42638f4428e70ead59d170f3d17ff761a0f < ab8b397d5997d8c37610252528edc54bebf9f6d3ab8b397d5997d8c37610252528edc54bebf9f6d3
linuxlinux>= 004ed42638f4428e70ead59d170f3d17ff761a0f < 8f5ffd2af7274853ff91d6cd62541191d9fbd10d8f5ffd2af7274853ff91d6cd62541191d9fbd10d
linuxlinux>= 004ed42638f4428e70ead59d170f3d17ff761a0f < a29cfcb848c31f22b4de6a531c3e1d68c9bfe09fa29cfcb848c31f22b4de6a531c3e1d68c9bfe09f
linuxlinux>= 004ed42638f4428e70ead59d170f3d17ff761a0f < 924f788c906dccaca30acab86c7124371e1d6f2c924f788c906dccaca30acab86c7124371e1d6f2c
linuxlinux>= 004ed42638f4428e70ead59d170f3d17ff761a0f < da0ffe84fcc1627a7dff82c80b823b94236af905da0ffe84fcc1627a7dff82c80b823b94236af905
linuxlinux>= 004ed42638f4428e70ead59d170f3d17ff761a0f < 6d45e1c948a8b7ed6ceddb14319af69424db730c6d45e1c948a8b7ed6ceddb14319af69424db730c
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.10.6-16.10.6-1
linuxlinux_kernel>= 0 < 6.10.6-16.10.6-1
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 5.11 < 5.15.1655.15.165
linuxlinux_kernel>= 5.16 < 6.1.1056.1.105
linuxlinux_kernel>= 5.8 < 5.10.2245.10.224
linuxlinux_kernel>= 6.2 < 6.6.466.6.46
linuxlinux_kernel>= 6.7 < 6.10.56.10.5
msrccbl2_kernel_5.15.164.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.167.1-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.