In the Linux kernel, the following vulnerability has been resolved:
fbdev: sis: Error out if pixclock equals zero
The userspace program could pass any values to the driver through
ioctl() interface. If the driver doesn't check the value of pixclock,
it may cause divide-by-zero error.
In sisfb_check_var(), var->pixclock is used as a divisor to caculate
drate before it is checked against zero. Fix this by checking it
at the beginning.
This is similar to CVE-2022-3061 in i740fb which was fixed by
commit 15cf0b8.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
27 Feb 2025, 14:34
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-369 | |
First Time |
Debian debian Linux
Debian Linux linux Kernel Linux |
|
CPE | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
References | () https://git.kernel.org/stable/c/1d11dd3ea5d039c7da089f309f39c4cd363b924b - Patch | |
References | () https://git.kernel.org/stable/c/6db07619d173765bd8622d63809cbfe361f04207 - Patch | |
References | () https://git.kernel.org/stable/c/84246c35ca34207114055a87552a1c4289c8fd7e - Patch | |
References | () https://git.kernel.org/stable/c/99f1abc34a6dde248d2219d64aa493c76bbdd9eb - Patch | |
References | () https://git.kernel.org/stable/c/cd36da760bd1f78c63c7078407baf01dd724f313 - Patch | |
References | () https://git.kernel.org/stable/c/df6e2088c6f4cad539cf67cba2d6764461e798d1 - Patch | |
References | () https://git.kernel.org/stable/c/e421946be7d9bf545147bea8419ef8239cb7ca52 - Patch | |
References | () https://git.kernel.org/stable/c/f329523f6a65c3bbce913ad35473d83a319d5d99 - Patch | |
References | () https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html - Mailing List | |
References | () https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html - Mailing List |
Information
Published : 2024-04-03 17:15
Updated : 2025-02-27 14:34
NVD link : CVE-2024-26777
Mitre link : CVE-2024-26777
CVE.ORG link : CVE-2024-26777
JSON object : View
Products Affected
linux
- linux_kernel
debian
- debian_linux
CWE
CWE-369
Divide By Zero