U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-47664

Change History

New CVE Received from kernel.org 10/09/2024 11:15:15 AM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

spi: hisi-kunpeng: Add verification for the max_frequency provided by the firmware

If the value of max_speed_hz is 0, it may cause a division by zero
error in hisi_calc_effective_speed().
The value of max_speed_hz is provided by firmware.
Firmware is generally considered as a trusted domain. However, as
division by zero errors can cause system failure, for defense measure,
the value of max_speed is validated here. So 0 is regarded as invalid
and an error code is returned.
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/16ccaf581da4fcf1e4d66086cf37263f9a656d43 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/5127c42c77de18651aa9e8e0a3ced190103b449c [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/ee73a15d4a8ce8fb02d7866f7cf78fcdd16f0fcc [No types assigned]