CVE-2022-49978 Details
Description
In the Linux kernel, the following vulnerability has been resolved: fbdev: fb_pm2fb: Avoid potential divide by zero error In `do_fb_ioctl()` of fbmem.c, if cmd is FBIOPUT_VSCREENINFO, var will be copied from user, then go through `fb_set_var()` and `info->fbops->fb_check_var()` which could may be `pm2fb_check_var()`. Along the path, `var->pixclock` won't be modified. This function checks whether reciprocal of `var->pixclock` is too high. If `var->pixclock` is zero, there will be a divide by zero error. So, it is necessary to check whether denominator is zero to avoid crash. As this bug is found by Syzkaller, logs are listed below. divide error in pm2fb_check_var Call Trace: <TASK> fb_set_var+0x367/0xeb0 drivers/video/fbdev/core/fbmem.c:1015 do_fb_ioctl+0x234/0x670 drivers/video/fbdev/core/fbmem.c:1110 fb_ioctl+0xdd/0x130 drivers/video/fbdev/core/fbmem.c:1189
A potential divide-by-zero vulnerability has been identified in the Linux kernel's framebuffer (fbdev) subsystem, specifically within the pm2fb_check_var function. When the FBIOPUT_VSCREENINFO command is processed, user-supplied data can lead to a situation where the var->pixclock value is zero. This oversight creates a risk of division by zero, which can cause a system crash. The issue arises because the fb_set_var function does not properly validate the pixclock value before it is used in a calculation that checks for excessively high pixel clock rates. The vulnerability was discovered by Syzkaller, a fuzzing tool that tests the robustness of software by introducing random data.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0f1174f4972ea9fad6becf8881d71adca8e9ca91 | kernel.org | Patch |
| https://git.kernel.org/stable/c/19f953e7435644b81332dd632ba1b2d80b1e37af | kernel.org | Patch |
| https://git.kernel.org/stable/c/34c3dea1189525cd533071ed5c176fc4ea8d982b | kernel.org | Patch |
| https://git.kernel.org/stable/c/3ec326a6a0d4667585ca595f438c7293e5ced7c4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7d9591b32a9092fc6391a316b56e8016c6181c3d | kernel.org | Patch |
| https://git.kernel.org/stable/c/7f88cdfea8d7f4dbaf423d808241403b2bb945e4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/8fc778ee2fb2853f7a3531fa7273349640d8e4e9 | kernel.org | Patch |
| https://git.kernel.org/stable/c/cb4bb011a683532841344ca7f281b5e04389b4f8 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-369 | Divide By Zero | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | < 4.9.327 >= 4.10, < 4.14.292 >= 4.15, < 4.19.257 >= 4.20, < 5.4.212 >= 5.5, < 5.10.141 >= 5.11, < 5.15.65 >= 5.16, < 5.19.7 6.0 rc1 6.0 rc2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Nov 14, 2025 | Initial Analysis | [email protected] |
| Jun 18, 2025 | New CVE Received | kernel.org |