cbcvebase.
CVE-2024-47663
published 2024-10-09

CVE-2024-47663: In the Linux kernel, the following vulnerability has been resolved: staging: iio: frequency: ad9834: Validate frequency parameter value In…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.7th percentile
In the Linux kernel, the following vulnerability has been resolved: staging: iio: frequency: ad9834: Validate frequency parameter value In ad9834_write_frequency() clk_get_rate() can return 0. In such case ad9834_calc_freqreg() call will lead to division by zero. Checking 'if (fout > (clk_freq / 2))' doesn't protect in case of 'fout' is 0. ad9834_write_frequency() is called from ad9834_write(), where fout is taken from text buffer, which can contain any value. Modify parameters checking. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= 12b9d5bf76bfa20d3207ef24fca9c8254a586a58 < 5edc3a45ef428501000a7b23d0e1777a548907f65edc3a45ef428501000a7b23d0e1777a548907f6
linuxlinux>= 12b9d5bf76bfa20d3207ef24fca9c8254a586a58 < 0e727707a239d5c519fc9abc2f0fd913516a7e470e727707a239d5c519fc9abc2f0fd913516a7e47
linuxlinux>= 12b9d5bf76bfa20d3207ef24fca9c8254a586a58 < 41cc91e3138fe52f8da92a81bebcd0e6cf488c5341cc91e3138fe52f8da92a81bebcd0e6cf488c53
linuxlinux>= 12b9d5bf76bfa20d3207ef24fca9c8254a586a58 < d8b09a5edc4a634373158c1a405491de3c52e58ad8b09a5edc4a634373158c1a405491de3c52e58a
linuxlinux>= 12b9d5bf76bfa20d3207ef24fca9c8254a586a58 < 3ba9abfcaa9e16bb91ed7e0e2b42e94a157a953e3ba9abfcaa9e16bb91ed7e0e2b42e94a157a953e
linuxlinux>= 12b9d5bf76bfa20d3207ef24fca9c8254a586a58 < dc12e49f970b08d8b007b8981b97e2eb93c0e89ddc12e49f970b08d8b007b8981b97e2eb93c0e89d
linuxlinux>= 12b9d5bf76bfa20d3207ef24fca9c8254a586a58 < 8961b245e8f92bccbaacfbbdf69eba60e3e7c2278961b245e8f92bccbaacfbbdf69eba60e3e7c227
linuxlinux>= 12b9d5bf76bfa20d3207ef24fca9c8254a586a58 < b48aa991758999d4e8f9296c5bbe388f293ef465b48aa991758999d4e8f9296c5bbe388f293ef465
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 2.6.38 < 5.4.2845.4.284
linuxlinux_kernel>= 5.11 < 5.15.1675.15.167
linuxlinux_kernel>= 5.16 < 6.1.1106.1.110
linuxlinux_kernel>= 5.5 < 5.10.2265.10.226
linuxlinux_kernel>= 6.2 < 6.6.516.6.51
linuxlinux_kernel>= 6.7 < 6.10.106.10.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.