CVE-2025-38519 – “Linux Kernel Divide by Zero Vulnerability in damon_get_intervals_score()”

The following table lists the changes that have been made to the
CVE-2025-38519 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 16, 2025

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved:

    mm/damon: fix divide by zero in damon_get_intervals_score()

    The current implementation allows having zero size regions with no special
    reasons, but damon_get_intervals_score() gets crashed by divide by zero
    when the region size is zero.

    [ 29.403950] Oops: divide error: 0000 [#1] SMP NOPTI

    This patch fixes the bug, but does not disallow zero size regions to keep
    the backward compatibility since disallowing zero size regions might be a
    breaking change for some users.

    In addition, the same crash can happen when intervals_goal.access_bp is
    zero so this should be fixed in stable trees as well.

    Added Reference https://git.kernel.org/stable/c/bd225b9591442065beb876da72656f4a2d627d03
    Added Reference https://git.kernel.org/stable/c/ca4bb9ac706f05ead8ac1cce7b8245fc0645a687
Share the Post:

Related Posts