CVE-2024-50205

MEDIUM EPSS 13.6%
Published Nov 8, 20241y ago · Modified Jun 17, 20262w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Nov 8, 2024 1y ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-lib: Avoid division by zero in apply_constraint_to_size() The step variable is initialized to zero. It is changed in the loop, but if it's not changed it will remain zero. Add a variable check before the division. The observed behavior was introduced by commit 826b5de90c0b ("ALSA: firewire-lib: fix insufficient PCM rule for period/buffer size"), and it is difficult to show that any of the interval parameters will satisfy the snd_interval_test() condition with data from the amdtp_rate_table[] table. Found by Linux Verification Center (linuxtesting.org) with SVACE.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
13.6% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-369

Affected Products 10

VendorProductVersionRange
linuxlinux_kernel*≥4.20  –  <5.4.285
linuxlinux_kernel*≥5.5  –  <5.10.229
linuxlinux_kernel*≥5.11  –  <5.15.170
linuxlinux_kernel*≥5.16  –  <6.1.115
linuxlinux_kernel*≥6.2  –  <6.6.59
linuxlinux_kernel*≥6.7  –  <6.11.6
linuxlinux_kernel6.12any
linuxlinux_kernel6.12any
linuxlinux_kernel6.12any
linuxlinux_kernel6.12any

References 10

  • cert-portal.siemens.com https://cert-portal.siemens.com/productcert/html/ssa-265688.html
  • git.kernel.org https://git.kernel.org/stable/c/3452d39c4704aa12504e4190298c721fb01083c3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4bdc21506f12b2d432b1f2667e5ff4c75eee58e3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5e431f85c87bbffd93a9830d5a576586f9855291
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/72cafe63b35d06b5cfbaf807e90ae657907858da
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7d4eb9e22131ec154e638cbd56629195c9bcbe9a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d2826873db70a6719cdd9212a6739f3e6234cfc4
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d575414361630b8b0523912532fcd7c79e43468c
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/3452d39c4704aa12504e4190298c721fb01083c3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4bdc21506f12b2d432b1f2667e5ff4c75eee58e3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5e431f85c87bbffd93a9830d5a576586f9855291
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/72cafe63b35d06b5cfbaf807e90ae657907858da
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7d4eb9e22131ec154e638cbd56629195c9bcbe9a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d2826873db70a6719cdd9212a6739f3e6234cfc4
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d575414361630b8b0523912532fcd7c79e43468c
    Patch