PT-2024-8302 · Linux+10 · Linux Kernel+10

Published

2024-03-02

·

Updated

2025-10-03

·

CVE-2024-27059

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a divide-by-zero error in the isd200 sub-driver of the usb-storage component. This error occurs when the sub-driver uses the HEADS and SECTORS values from the ATA ID information to calculate cylinder and head values for READ or WRITE commands. If either of these values is 0, the calculation will cause a crash. This could happen with a flawed or subversive emulation, as reported by the syzbot fuzzer. The protection against this possibility involves refusing to bind to the device if either the ATA ID HEADS or ATA ID SECTORS value in the device's ID information is 0. This requires the isd200 Initialization() function to return a negative error code when initialization fails.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Divide By Zero

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:3618
ALSA-2024:3627
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-17893
ALT-PU-2025-12647
AZL-55536
BDU:2024-09855
CESA-2024_3618
CESA-2024_3627
CVE-2024-27059
DLA-3840-1
DLA-3842-1
DSA-5681-1
INFSA-2024_3618
INFSA-2024_3627
OESA-2024-1677
OESA-2024-1678
OESA-2024-1679
OESA-2024-1680
OESA-2024-1681
OESA-2024-1682
OPENSUSE-SU-2024_1644-1
RHSA-2024:3618
RHSA-2024:3627
RHSA-2024_3618
RHSA-2024_3627
RHSA-2025:13135
RLSA-2024:3618
RLSA-2024:3627
SUSE-SU-2024:1644-1
SUSE-SU-2024:1979-1
SUSE-SU-2024:1983-1
SUSE-SU-2024:2008-1
SUSE-SU-2024:2184-1
SUSE-SU-2024:2190-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6896-1
USN-6896-2
USN-6896-3
USN-6896-4
USN-6896-5
USN-6898-1
USN-6898-2
USN-6898-3
USN-6898-4
USN-6917-1
USN-6919-1
USN-6927-1
USN-7019-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu