CVE-2024-26778

In the Linux kernel, the following vulnerability has been resolved: fbdev: savage: Error out if pixclock equals zero The userspace program could pass any values to the driver through ioctl() interface. If the driver doesn't check the value of pixclock, it may cause divide-by-zero error. Although pixclock is checked in savagefb_decode_var(), but it is not checked properly in savagefb_probe(). Fix this by checking whether pixclock is zero in the function savagefb_check_var() before info->var.pixclock is used as the divisor. This is similar to CVE-2022-3061 in i740fb which was fixed by commit 15cf0b8.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

27 Feb 2025, 14:34

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/04e5eac8f3ab2ff52fa191c187a46d4fdbc1e288 - () https://git.kernel.org/stable/c/04e5eac8f3ab2ff52fa191c187a46d4fdbc1e288 - Patch
References () https://git.kernel.org/stable/c/070398d32c5f3ab0e890374904ad94551c76aec4 - () https://git.kernel.org/stable/c/070398d32c5f3ab0e890374904ad94551c76aec4 - Patch
References () https://git.kernel.org/stable/c/224453de8505aede1890f007be973925a3edf6a1 - () https://git.kernel.org/stable/c/224453de8505aede1890f007be973925a3edf6a1 - Patch
References () https://git.kernel.org/stable/c/512ee6d6041e007ef5bf200c6e388e172a2c5b24 - () https://git.kernel.org/stable/c/512ee6d6041e007ef5bf200c6e388e172a2c5b24 - Patch
References () https://git.kernel.org/stable/c/84dce0f6a4cc5b7bfd7242ef9290db8ac1dd77ff - () https://git.kernel.org/stable/c/84dce0f6a4cc5b7bfd7242ef9290db8ac1dd77ff - Patch
References () https://git.kernel.org/stable/c/8c54acf33e5adaad6374bf3ec1e3aff0591cc8e1 - () https://git.kernel.org/stable/c/8c54acf33e5adaad6374bf3ec1e3aff0591cc8e1 - Patch
References () https://git.kernel.org/stable/c/a9ca4e80d23474f90841251f4ac0d941fa337a01 - () https://git.kernel.org/stable/c/a9ca4e80d23474f90841251f4ac0d941fa337a01 - Patch
References () https://git.kernel.org/stable/c/bc3c2e58d73b28b9a8789fca84778ee165a72d13 - () https://git.kernel.org/stable/c/bc3c2e58d73b28b9a8789fca84778ee165a72d13 - Patch
References () https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html - () https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html - Mailing List
References () https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html - () https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html - Mailing List
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-369
CPE cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Debian debian Linux
Debian
Linux linux Kernel
Linux

Information

Published : 2024-04-03 17:15

Updated : 2025-02-27 14:34


NVD link : CVE-2024-26778

Mitre link : CVE-2024-26778

CVE.ORG link : CVE-2024-26778


JSON object : View

Products Affected

linux

  • linux_kernel

debian

  • debian_linux
CWE
CWE-369

Divide By Zero