cbcvebase.
CVE-2024-56369
published 2025-01-11

CVE-2024-56369: In the Linux kernel, the following vulnerability has been resolved: drm/modes: Avoid divide by zero harder in drm_mode_vrefresh() drm_mode_vrefresh() is trying…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.4th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/modes: Avoid divide by zero harder in drm_mode_vrefresh() drm_mode_vrefresh() is trying to avoid divide by zero by checking whether htotal or vtotal are zero. But we may still end up with a div-by-zero of vtotal*htotal*...

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 2f0e9d804935970a4ce0f58dd046b41881bfd8f3 < e7c7b48a0fc5ed83baae400a1b15e33978c25d7fe7c7b48a0fc5ed83baae400a1b15e33978c25d7f
linuxlinux>= 2f0e9d804935970a4ce0f58dd046b41881bfd8f3 < 69fbb01e891701e6d04db1ddb5ad49e42c4dd96369fbb01e891701e6d04db1ddb5ad49e42c4dd963
linuxlinux>= 2f0e9d804935970a4ce0f58dd046b41881bfd8f3 < b39de5a71bac5641d0fda33d1cf5682d82cf1ae5b39de5a71bac5641d0fda33d1cf5682d82cf1ae5
linuxlinux>= 2f0e9d804935970a4ce0f58dd046b41881bfd8f3 < 47c8b6cf1d08f0ad40d7ea7b025442e51b35ee1f47c8b6cf1d08f0ad40d7ea7b025442e51b35ee1f
linuxlinux>= 2f0e9d804935970a4ce0f58dd046b41881bfd8f3 < 9398332f23fab10c5ec57c168b44e72997d6318e9398332f23fab10c5ec57c168b44e72997d6318e
linuxlinux_kernel< 5.15.1765.15.176
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.8-16.12.8-1
linuxlinux_kernel>= 0 < 6.12.8-16.12.8-1
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 5.16 < 6.1.1226.1.122
linuxlinux_kernel>= 6.2 < 6.6.686.6.68
linuxlinux_kernel>= 6.7 < 6.12.76.12.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.