Junglewise Threat Intelligence

CVE-2024-35922: Linux Kernel division by zero in fb_videomode_from_videomode

CVE-2024-35922 · Severity: medium · CVSS 5.5 · Published 2024-05-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's video monitor handling component. An error in how the system calculates video display modes could allow a local user to cause a system crash or denial of service. This affects the stability of the operating system but does not directly expose user data.

Technical details

A division by zero vulnerability exists in the Linux kernel's fbmon component within the fb_videomode_from_videomode() function. The root cause is an integer overflow when calculating the product of 'htotal' and 'vtotal', which can result in a zero value being used as a divisor when calculating the refresh rate. A local attacker with basic privileges could potentially trigger this condition to cause a kernel oops or system crash. The issue has been resolved in various stable branches including 4.19.312, 5.4.274, 5.10.215, 5.15.155, 6.1.86, 6.6.27, and 6.8.6.

Affected products

  • Linux Linux Kernel versions up to 4.19.312, 4.20 to 5.4.274, 5.5 to 5.10.215, 5.11 to 5.15.155, 5.16 to 6.1.86, 6.2 to 6.6.27, 6.7 to 6.8.6

Timeline

  • 2024-05-19: disclosed
  • 2024-05-19: advisory

References

Related threats