PT-2024-34040 · Linux+7 · Linux Kernel+7
Andrey Shumilin
·
Published
2024-11-07
·
Updated
2025-10-03
·
CVE-2024-50205
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.6.61
Description:
A division by zero vulnerability has been resolved in the Linux kernel, specifically in the ALSA firewire-lib component. The issue occurred in the
apply constraint to size() function, where the step variable was initialized to zero and could remain zero if not changed in the loop, leading to a division by zero error. This behavior was introduced by a previous commit and was difficult to identify due to the complexity of the snd interval test() condition and the amdtp rate table[] table. The vulnerability was found by the Linux Verification Center with SVACE.Recommendations:
For Linux kernel versions prior to 6.6.61, update to version 6.6.61 or later to resolve the issue. As a temporary workaround, consider adding a variable check before the division in the
apply constraint to size() function to prevent the division by zero error.Exploit
Fix
Use of Uninitialized Resource
Divide By Zero
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu