CVE-2022-50010
Published: Jun 18, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: video: fbdev: i740fb: Check the argument of i740_calc_vclk() Since the user can control the arguments of the ioctl() from the user space, under special arguments that may result in a divide-by-zero bug. If the user provides an improper 'pixclock' value that makes the argumet of i740_calc_vclk() less than 'I740_RFREQ_FIX', it will cause a divide-by-zero bug in: drivers/video/fbdev/i740fb.c:353 p_best = min(15, ilog2(I740_MAX_VCO_FREQ / (freq / I740_RFREQ_FIX))); The following log can reveal it: divide error: 0000 [#1] PREEMPT SMP KASAN PTI RIP: 0010:i740_calc_vclk drivers/video/fbdev/i740fb.c:353 [inline] RIP: 0010:i740fb_decode_var drivers/video/fbdev/i740fb.c:646 [inline] RIP: 0010:i740fb_set_par+0x163f/0x3b70 drivers/video/fbdev/i740fb.c:742 Call Trace: fb_set_var+0x604/0xeb0 drivers/video/fbdev/core/fbmem.c:1034 do_fb_ioctl+0x234/0x670 drivers/video/fbdev/core/fbmem.c:1110 fb_ioctl+0xdd/0x130 drivers/video/fbdev/core/fbmem.c:1189 Fix this by checking the argument of i740_calc_vclk() first.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 5350c65f4f15bbc111ffa629130d3f32cdd4ccf6 - < 59cefb583c984c0da8cf21a4c57d26d5a20dff5caffected 5350c65f4f15bbc111ffa629130d3f32cdd4ccf6 - < 656689cb03ada4650016c153346939a1c334b1aeaffected 5350c65f4f15bbc111ffa629130d3f32cdd4ccf6 - < d2d375eb68b4b8de6ea7460483a26fa9de56b443affected 5350c65f4f15bbc111ffa629130d3f32cdd4ccf6 - < 2b7f559152a33c55f51b569b22efbe5e24886798affected 5350c65f4f15bbc111ffa629130d3f32cdd4ccf6 - < 4b20c61365140d432dee7da7aa294215e7b900d9+3 more versions |
Linux | Linux | affected 3.4unaffected 0 - < 3.4unaffected 4.9.326 - <= 4.9.*unaffected 4.14.291 - <= 4.14.*unaffected 4.19.256 - <= 4.19.*+5 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now