Junglewise Threat Intelligence

CVE-2024-43889: Linux Kernel divide-by-zero panic in padata_mt_helper

CVE-2024-43889 · Severity: medium · CVSS 5.5 · Published 2024-08-26

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's parallel data processing component (padata) can cause the system to crash during startup or operation. This occurs due to a mathematical error (division by zero) when the system attempts to manage multi-threaded tasks with specific configurations. An exploit would result in a complete system denial of service, requiring a reboot to recover.

Technical details

A divide-by-zero vulnerability exists in the padata_mt_helper() function within kernel/padata.c. The root cause is that the 'chunk_size' variable can be initialized to zero in padata_do_multithreaded() if the 'min_chunk' parameter in the padata_mt_job structure is set to zero by a caller. When this zero value is subsequently used in division operations within the helper function, it triggers a kernel panic (Oops: divide error). The fix ensures chunk_size is at least 1. This is reachable by local users with sufficient privileges to trigger multithreaded padata jobs, primarily impacting system availability.

Affected products

  • Linux Linux Kernel 5.8 to 5.10.224, 5.11 to 5.15.165, 5.16 to 6.1.105, 6.2 to 6.6.46, 6.7 to 6.10.5

Timeline

  • 2024-08-06: patched: Initial patch submitted by Waiman Long
  • 2024-08-26: advisory: CVE-2024-43889 published

References

Related threats