CVE-2022-49294
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check if modulo is 0 before dividing. [How & Why] If
CVSS
5.5
Medium
EPSS
0.3%
p18
KEV
—
Exploit Today
5
0-100
Published: Feb 26, 2025 · Last modified: Aug 13, 2026 · CWE-369
0.3%EPSS · 30 days0.3%
2026-08-032026-08-31
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check if modulo is 0 before dividing. [How & Why] If a value of 0 is read, then this will cause a divide-by-0 panic.
- git.kernel.orghttps://git.kernel.org/stable/c/07efce8269a038c37814eb656b4de14aa3015fc6
- git.kernel.orghttps://git.kernel.org/stable/c/10ef82d6e0af5536ec64770c07f6bbabfdd6977c
- git.kernel.orghttps://git.kernel.org/stable/c/49947b906a6bd9668eaf4f9cf691973c25c26955
- git.kernel.orghttps://git.kernel.org/stable/c/96725758eff7b3805e4e94d1443a100757412720
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-754666.5 MED9.7%
——3libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexed-color PNG image with a non-gray palette through tj3LoadImage12() or tj3LoadImage16() using the default pixel format, the application may trigger a division-by-zero in alloc_sarray(), causing a SIGFPE and denial of service.5dCVE-2026-718326.2 MED1.9%
——1Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial of Service4dCVE-2026-168974.4 MED1.5%
——0IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of-bounds write.12dCVE-2026-631176.5 MED31.9%
——10FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated RDP client can advertise DVI ADPCM with nBlockAlign equal to 8 and nChannels equal to 2 to make the `bs` calculation in rdpsnd_server_select_format in channels/rdpsnd/server/rdpsnd_main.c equal zero. The subsequent out_frames modulo `bs` operation raises SIGFPE and terminates the server-side rdpsnd channel process. This vulnerability fixed in 3.28.0.13dCVE-2026-649513.5 LOW5.8%
——2A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic occurs which may crash the server process.
The problem is a Divide by Zero bug in the ShouldPadFile() function.4dCVE-2026-175356.2 MED1.9%
——1Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images.
Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting the opportunity of attackers corrupting the filesystem. However, in some applications (e.g. dead disk forensics https://docs.velociraptor.app/docs/forensic/deaddisk/ ) Velociraptor may be used on untrusted NTFS image files.
If an attacker is able to inject maliciously corrupted NTFS Volumes they can cause a crash and a Denial of Service.4d