cbcvebase.
CVE-2024-43893
published 2024-08-26

CVE-2024-43893: In the Linux kernel, the following vulnerability has been resolved: serial: core: check uartclk for zero to avoid divide by zero Calling ioctl TIOCSSERIAL with…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.3th percentile
In the Linux kernel, the following vulnerability has been resolved: serial: core: check uartclk for zero to avoid divide by zero Calling ioctl TIOCSSERIAL with an invalid baud_base can result in uartclk being zero, which will result in a divide by zero error in uart_get_divisor(). The check for uartclk being zero in uart_set_info() needs to be done before other settings are made as subsequent calls to ioctl TIOCSSERIAL for the same port would be impacted if the uartclk check was done where uartclk gets set. Oops: divide error: 0000 PREEMPT SMP KASAN PTI RIP: 0010:uart_get_divisor (drivers/tty/serial/serial_core.c:580) Call Trace: serial8250_get_divisor (drivers/tty/serial/8250/8250_port.c:2576 drivers/tty/serial/8250/8250_port.c:2589) serial8250_do_set_termios (drivers/tty/serial/8250/8250_port.c:502 drivers/tty/serial/8250/8250_port.c:2741) serial8250_set_termios (drivers/tty/serial/8250/8250_port.c:2862) uart_change_line_settings (./include/linux/spinlock.h:376 ./include/linux/serial_core.h:608 drivers/tty/serial/serial_core.c:222) uart_port_startup (drivers/tty/serial/serial_core.c:342) uart_startup (drivers/tty/serial/serial_core.c:368) uart_set_info (drivers/tty/serial/serial_core.c:1034) uart_set_info_user (drivers/tty/serial/serial_core.c:1059) tty_set_serial (drivers/tty/tty_io.c:2637) tty_ioctl (drivers/tty/tty_io.c:2647 drivers/tty/tty_io.c:2791) __x64_sys_ioctl (fs/ioctl.c:52 fs/ioctl.c:907 fs/ioctl.c:893 fs/ioctl.c:893) do_syscall_64 (arch/x86/entry/common.c:52 (discriminator 1) arch/x86/entry/common.c:83 (discriminator 1)) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) Rule: add

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3bbd90fca824e6fd61fb20f6dd2b0fa5f8b14bba3bbd90fca824e6fd61fb20f6dd2b0fa5f8b14bba
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 55b2a5d331a6ceb1c4372945fdb77181265ba24f55b2a5d331a6ceb1c4372945fdb77181265ba24f
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 52b138f1021113e593ee6ad258ce08fe90693a9e52b138f1021113e593ee6ad258ce08fe90693a9e
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9196e42a3b8eeff1707e6ef769112b4b6096be499196e42a3b8eeff1707e6ef769112b4b6096be49
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e13ba3fe5ee070f8a9dab60029d52b1f61da5051e13ba3fe5ee070f8a9dab60029d52b1f61da5051
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e3ad503876283ac3fcca922a1bf243ef9eb0b0e2e3ad503876283ac3fcca922a1bf243ef9eb0b0e2
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 68dc02f319b9ee54dc23caba742a5c754d1cccc868dc02f319b9ee54dc23caba742a5c754d1cccc8
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6eabce6608d6f3440f4c03aa3d3ef50a47a3d1936eabce6608d6f3440f4c03aa3d3ef50a47a3d193
linuxlinux_kernel< 4.19.3204.19.320
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.10.6-16.10.6-1
linuxlinux_kernel>= 0 < 6.10.6-16.10.6-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 0 < 4.4.0-266.3004.4.0-266.300
linuxlinux_kernel>= 0 < 4.15.0-235.2474.15.0-235.247
linuxlinux_kernel>= 4.20 < 5.4.2825.4.282
linuxlinux_kernel>= 5.11 < 5.15.1655.15.165
linuxlinux_kernel>= 5.16 < 6.1.1056.1.105

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.