cbcvebase.
CVE-2024-49977
published 2024-10-21

CVE-2024-49977: In the Linux kernel, the following vulnerability has been resolved: net: stmmac: Fix zero-division error when disabling tc cbs The commit b8c43360f6e4 ("net…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.0th percentile
In the Linux kernel, the following vulnerability has been resolved: net: stmmac: Fix zero-division error when disabling tc cbs The commit b8c43360f6e4 ("net: stmmac: No need to calculate speed divider when offload is disabled") allows the "port_transmit_rate_kbps" to be set to a value of 0, which is then passed to the "div_s64" function when tc-cbs is disabled. This leads to a zero-division error. When tc-cbs is disabled, the idleslope, sendslope, and credit values the credit values are not required to be configured. Therefore, adding a return statement after setting the txQ mode to DCB when tc-cbs is disabled would prevent a zero-division error.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 2145583e5995598f50d66f8710c86bb1e910ac46 < b0da9504a528f05f97d926b4db74ff21917a33e9b0da9504a528f05f97d926b4db74ff21917a33e9
linuxlinux>= 5.10.221 < 5.10.2275.10.227
linuxlinux>= 5.15.162 < 5.15.1685.15.168
linuxlinux>= 521d42a1c24d638241220d4b9fa7e7a0ed02b88e < 5d43e1ad4567d67af2b42d3ab7c14152ffed25c65d43e1ad4567d67af2b42d3ab7c14152ffed25c6
linuxlinux>= 6.1.96 < 6.1.1136.1.113
linuxlinux>= 6.6.36 < 6.6.556.6.55
linuxlinux>= 6.9.7 < 6.106.10
linuxlinux>= a71b686418ee6bcb6d6365f7f6d838d9874d9c64 < 03582f4752427f60817d896f1a827aff772bd31e03582f4752427f60817d896f1a827aff772bd31e
linuxlinux>= b4bca4722fda928810d024350493990de39f1e40 < e33fe25b1efe4f2e6a5858786dbc82ae4c44ed4ce33fe25b1efe4f2e6a5858786dbc82ae4c44ed4c
linuxlinux>= b8c43360f6e424131fa81d3ba8792ad8ff25a09e < e297a2bf56d12fd7f91a0c209eb6ea84361f3368e297a2bf56d12fd7f91a0c209eb6ea84361f3368
linuxlinux>= b8c43360f6e424131fa81d3ba8792ad8ff25a09e < 837d9df9c0792902710149d1a5e0991520af0f93837d9df9c0792902710149d1a5e0991520af0f93
linuxlinux>= b8c43360f6e424131fa81d3ba8792ad8ff25a09e < 675faf5a14c14a2be0b870db30a70764df81e2df675faf5a14c14a2be0b870db30a70764df81e2df
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-54.566.8.0-54.56
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.10.221 < 5.10.2275.10.227
linuxlinux_kernel>= 5.15.162 < 5.15.1685.15.168

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.