In the Linux kernel, the following vulnerability has been resolved:
video: fbdev: cirrusfb: check pixclock to avoid divide by zero
Do a sanity check on pixclock value to avoid divide by zero.
If the pixclock value is zero, the cirrusfb driver will round up pixclock to get the derived frequency as close to maxclock as possible.
Syzkaller reported a divide error in cirrusfb_check_pixclock.
divide error: 0000 [#1] SMP KASAN PTI CPU: 0 PID: 14938 Comm: cirrusfb_test Not tainted 5.15.0-rc6 #1 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.11.0-2 RIP: 0010:cirrusfb_check_var+0x6f1/0x1260
Call Trace: fb_set_var+0x398/0xf90 do_fb_ioctl+0x4b8/0x6f0 fb_ioctl+0xeb/0x130 __x64_sys_ioctl+0x19d/0x220 do_syscall_64+0x3a/0x80 entry_SYSCALL_64_after_hwframe+0x44/0xae
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Ubuntu | — | Upgrade linux-azure-fipsUpgrade linux-azure-fde-5.15Upgrade linux-gcp-5.4Upgrade linux-lowlatencyUpgrade linux-oracle-5.4Upgrade linux-aws-5.4Upgrade linux-aws-hweUpgrade linux-gkeUpgrade linuxUpgrade linux-ibm-5.4Upgrade linux-lowlatency-hwe-5.15Upgrade linux-fipsUpgrade linux-gcpUpgrade linux-intel-iotgUpgrade linux-realtimeUpgrade linux-bluefieldUpgrade linux-raspi-5.4Upgrade linux-gcp-4.15Upgrade linux-azure-4.15Upgrade linux-hweUpgrade linux-oracleUpgrade linux-ibmUpgrade linux-kvmUpgrade linux-hwe-5.4Upgrade linux-intel-iotg-5.15Upgrade linux-raspiUpgrade linux-aws-fipsUpgrade linux-iotUpgrade linux-hwe-5.15Upgrade linux-gcp-fipsUpgrade linux-awsUpgrade linux-azure-5.4Upgrade linux-azureUpgrade linux-azure-5.15 | Mar 3, 2025 | Feb 26, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub