Executive brief
A vulnerability in the Linux kernel's USB storage driver could allow a malicious or malfunctioning USB device to crash the operating system. By providing invalid storage information during the connection process, the device triggers a mathematical error (division by zero) in the kernel. This results in a system crash or 'kernel panic,' leading to a denial of service for the affected machine.
Technical details
A divide-by-zero vulnerability exists in the isd200 sub-driver of the usb-storage component in the Linux kernel. The root cause is located in the isd200_ata_command function, which uses ATA_ID_HEADS and ATA_ID_SECTORS values from a device's ID information to calculate cylinder and head values via division and modulus operations. If a device (or an emulated subversive device) provides a value of 0 for these fields, the kernel triggers a division-by-zero error, leading to a crash. The fix involves validating these values during device initialization and refusing to bind to devices that provide invalid ATA identification data.
Affected products
- Linux Linux Kernel 2.6.12 to 4.19.312, 4.20 to 5.4.274, 5.5 to 5.10.215, 5.11 to 5.15.154, 5.16 to 6.1.84, 6.2 to 6.6.64, 6.7 to 6.7.12, 6.8-rc1 to 6.8-rc6
Timeline
- 2024-02-29: other: Vulnerability reported and tested by syzbot
- 2024-03-02: patched: Initial patch committed to stable tree
- 2024-05-01: disclosed: CVE published
References
- https://git.kernel.org/stable/c/014bcf41d946b36a8f0b8e9b5d9529efbb822f49
- https://git.kernel.org/stable/c/284fb1003d5da111019b9e0bf99b084fd71ac133
- https://git.kernel.org/stable/c/3a67d4ab9e730361d183086dfb0ddd8c61f01636
- https://git.kernel.org/stable/c/6c1f36d92c0a8799569055012665d2bb066fb964
- https://git.kernel.org/stable/c/871fd7b10b56d280990b7e754f43d888382ca325
- https://git.kernel.org/stable/c/9968c701cba7eda42e5f0052b040349d6222ae34
- https://git.kernel.org/stable/c/eb7b01ca778170654e1c76950024270ba74b121f