iio: adc: ad7124: fix division by zero in ad7124_set_channel_odr()
Published Nov 9, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.25%
Description
In the ad7124_write_raw() function, parameter val can potentially be zero. This may lead to a division by zero when DIV_ROUND_CLOSEST() is called within ad7124_set_channel_odr(). The ad7124_write_raw() function is invoked through the sequence: iio_write_channel_raw() -> iio_write_channel_attribute() -> iio_channel_write(), with no checks in place to ensure val is non-zero.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.13StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.13
- Version 5.15.171StatusunaffectedConstraints<=5.15.*
- Version 6.1.116StatusunaffectedConstraints<=6.1.*
- Version 6.11.7StatusunaffectedConstraints<=6.11.*
- Version 6.12StatusunaffectedConstraints<=*
- Version 6.6.60StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.13 · < 5.15.171
- ≥ 5.16 · < 6.1.116
- ≥ 6.2 · < 6.6.60
- ≥ 6.7 · < 6.11.7
- 6.12
- 6.12
- 6.12
- 6.12
- 6.12
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2024-50232 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2324880 Issue Tracking
- https://git.kernel.org/stable/c/0ac0beb4235a9a474f681280a3bd4e2a5bb66569 Patch
- https://git.kernel.org/stable/c/3dc0eda2cd5c653b162852ae5f0631bfe4ca5e95 Patch
- https://git.kernel.org/stable/c/4f588fffc307a4bc2761aee6ff275bb4b433e451 Patch
- https://git.kernel.org/stable/c/efa353ae1b0541981bc96dbf2e586387d0392baa Patch
- https://git.kernel.org/stable/c/f51343f346e6abde094548a7fb34472b0d4cae91 Patch
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
- https://lore.kernel.org/linux-cve-announce/2024110930-CVE-2024-50232-d425@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-50232
- https://www.cve.org/CVERecord?id=CVE-2024-50232
Change history (0)
No recorded changes yet.