Executive brief
A vulnerability in the Linux kernel's audio subsystem for FireWire devices could allow a local user to crash the system. The issue occurs when the system attempts to process specific audio parameters, leading to a mathematical error that halts the operating system. This primarily impacts system availability and could be used to cause a denial-of-service.
Technical details
A division-by-zero vulnerability exists in the apply_constraint_to_size() function within sound/firewire/amdtp-stream.c of the Linux kernel. The 'step' variable, used as a divisor in the roundup() and rounddown() macros, is initialized to zero and may remain zero if no interval parameters satisfy the snd_interval_test() condition. A local attacker can trigger this condition to cause a kernel panic. The issue was introduced in commit 826b5de90c0b and has been fixed by adding a check to return -EINVAL if 'step' is zero.
Affected products
- Linux Linux Kernel 4.20 to 5.4.284, 5.5 to 5.10.228, 5.11 to 5.15.169, 5.16 to 6.1.114, 6.2 to 6.6.58, 6.7 to 6.11.5
Timeline
- 2024-10-21: patched: Initial fix in mainline kernel tree
- 2024-11-08: disclosed: CVE assigned and published
References
- https://git.kernel.org/stable/c/3452d39c4704aa12504e4190298c721fb01083c3
- https://git.kernel.org/stable/c/4bdc21506f12b2d432b1f2667e5ff4c75eee58e3
- https://git.kernel.org/stable/c/5e431f85c87bbffd93a9830d5a576586f9855291
- https://git.kernel.org/stable/c/72cafe63b35d06b5cfbaf807e90ae657907858da
- https://git.kernel.org/stable/c/7d4eb9e22131ec154e638cbd56629195c9bcbe9a
- https://git.kernel.org/stable/c/d2826873db70a6719cdd9212a6739f3e6234cfc4
- https://git.kernel.org/stable/c/d575414361630b8b0523912532fcd7c79e43468c