Junglewise Threat Intelligence

CVE-2024-27059: Linux Kernel divide-by-zero error in USB isd200 sub-driver

CVE-2024-27059 · Severity: medium · CVSS 5.5 · Published 2024-05-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's USB storage driver could allow a malicious or malfunctioning USB device to crash the operating system. By providing invalid storage information during the connection process, the device triggers a mathematical error (division by zero) in the kernel. This results in a system crash or 'kernel panic,' leading to a denial of service for the affected machine.

Technical details

A divide-by-zero vulnerability exists in the isd200 sub-driver of the usb-storage component in the Linux kernel. The root cause is located in the isd200_ata_command function, which uses ATA_ID_HEADS and ATA_ID_SECTORS values from a device's ID information to calculate cylinder and head values via division and modulus operations. If a device (or an emulated subversive device) provides a value of 0 for these fields, the kernel triggers a division-by-zero error, leading to a crash. The fix involves validating these values during device initialization and refusing to bind to devices that provide invalid ATA identification data.

Affected products

  • Linux Linux Kernel 2.6.12 to 4.19.312, 4.20 to 5.4.274, 5.5 to 5.10.215, 5.11 to 5.15.154, 5.16 to 6.1.84, 6.2 to 6.6.64, 6.7 to 6.7.12, 6.8-rc1 to 6.8-rc6

Timeline

  • 2024-02-29: other: Vulnerability reported and tested by syzbot
  • 2024-03-02: patched: Initial patch committed to stable tree
  • 2024-05-01: disclosed: CVE published

References

Related threats