CVE-2024-26777

In the Linux kernel, the following vulnerability has been resolved: fbdev: sis: Error out if pixclock equals zero The userspace program could pass any values to the driver through ioctl() interface. If the driver doesn't check the value of pixclock, it may cause divide-by-zero error. In sisfb_check_var(), var->pixclock is used as a divisor to caculate drate before it is checked against zero. Fix this by checking it at the beginning. This is similar to CVE-2022-3061 in i740fb which was fixed by commit 15cf0b8.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

27 Feb 2025, 14:34

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE CWE-369
References () https://git.kernel.org/stable/c/1d11dd3ea5d039c7da089f309f39c4cd363b924b - () https://git.kernel.org/stable/c/1d11dd3ea5d039c7da089f309f39c4cd363b924b - Patch
References () https://git.kernel.org/stable/c/6db07619d173765bd8622d63809cbfe361f04207 - () https://git.kernel.org/stable/c/6db07619d173765bd8622d63809cbfe361f04207 - Patch
References () https://git.kernel.org/stable/c/84246c35ca34207114055a87552a1c4289c8fd7e - () https://git.kernel.org/stable/c/84246c35ca34207114055a87552a1c4289c8fd7e - Patch
References () https://git.kernel.org/stable/c/99f1abc34a6dde248d2219d64aa493c76bbdd9eb - () https://git.kernel.org/stable/c/99f1abc34a6dde248d2219d64aa493c76bbdd9eb - Patch
References () https://git.kernel.org/stable/c/cd36da760bd1f78c63c7078407baf01dd724f313 - () https://git.kernel.org/stable/c/cd36da760bd1f78c63c7078407baf01dd724f313 - Patch
References () https://git.kernel.org/stable/c/df6e2088c6f4cad539cf67cba2d6764461e798d1 - () https://git.kernel.org/stable/c/df6e2088c6f4cad539cf67cba2d6764461e798d1 - Patch
References () https://git.kernel.org/stable/c/e421946be7d9bf545147bea8419ef8239cb7ca52 - () https://git.kernel.org/stable/c/e421946be7d9bf545147bea8419ef8239cb7ca52 - Patch
References () https://git.kernel.org/stable/c/f329523f6a65c3bbce913ad35473d83a319d5d99 - () https://git.kernel.org/stable/c/f329523f6a65c3bbce913ad35473d83a319d5d99 - Patch
References () https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html - () https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html - Mailing List
References () https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html - () https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html - Mailing List
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Debian
Linux linux Kernel
Linux
Debian debian Linux

21 Nov 2024, 09:03

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html -
  • () https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html -
References () https://git.kernel.org/stable/c/1d11dd3ea5d039c7da089f309f39c4cd363b924b - () https://git.kernel.org/stable/c/1d11dd3ea5d039c7da089f309f39c4cd363b924b -
References () https://git.kernel.org/stable/c/6db07619d173765bd8622d63809cbfe361f04207 - () https://git.kernel.org/stable/c/6db07619d173765bd8622d63809cbfe361f04207 -
References () https://git.kernel.org/stable/c/84246c35ca34207114055a87552a1c4289c8fd7e - () https://git.kernel.org/stable/c/84246c35ca34207114055a87552a1c4289c8fd7e -
References () https://git.kernel.org/stable/c/99f1abc34a6dde248d2219d64aa493c76bbdd9eb - () https://git.kernel.org/stable/c/99f1abc34a6dde248d2219d64aa493c76bbdd9eb -
References () https://git.kernel.org/stable/c/cd36da760bd1f78c63c7078407baf01dd724f313 - () https://git.kernel.org/stable/c/cd36da760bd1f78c63c7078407baf01dd724f313 -
References () https://git.kernel.org/stable/c/df6e2088c6f4cad539cf67cba2d6764461e798d1 - () https://git.kernel.org/stable/c/df6e2088c6f4cad539cf67cba2d6764461e798d1 -
References () https://git.kernel.org/stable/c/e421946be7d9bf545147bea8419ef8239cb7ca52 - () https://git.kernel.org/stable/c/e421946be7d9bf545147bea8419ef8239cb7ca52 -
References () https://git.kernel.org/stable/c/f329523f6a65c3bbce913ad35473d83a319d5d99 - () https://git.kernel.org/stable/c/f329523f6a65c3bbce913ad35473d83a319d5d99 -

05 Nov 2024, 10:15

Type Values Removed Values Added
References
  • {'url': 'https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html', 'source': '416baaa9-dc9f-4396-8d5f-8c081fb06d67'}
  • {'url': 'https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html', 'source': '416baaa9-dc9f-4396-8d5f-8c081fb06d67'}

27 Jun 2024, 13:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html -

25 Jun 2024, 22:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html -
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: fbdev: sis: error si pixclock es igual a cero. El programa de espacio de usuario podría pasar cualquier valor al controlador a través de la interfaz ioctl(). Si el controlador no verifica el valor de pixclock, puede causar un error de división por cero. En sisfb_check_var(), var->pixclock se usa como divisor para calcular la velocidad antes de compararla con cero. Solucione este problema marcándolo al principio. Esto es similar a CVE-2022-3061 en i740fb que se solucionó mediante el commit 15cf0b8.

03 Apr 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-03 17:15

Updated : 2025-02-27 14:34


NVD link : CVE-2024-26777

Mitre link : CVE-2024-26777

CVE.ORG link : CVE-2024-26777


JSON object : View

Products Affected

debian

  • debian_linux

linux

  • linux_kernel
CWE
CWE-369

Divide By Zero