Linux Kernel Division by Zero Vulnerability in net: hibmcge Component

Vulnerability

A division by zero vulnerability has been identified in the Linux kernel's net: hibmcge component. This issue occurs when the network port is down, causing the queue to be released and the ring length to become zero. In this state, a function called hbg_get_queue_used_num() may be invoked, leading to a potential division by zero error. The vulnerability affects several versions of the Linux kernel.

Impact

Exploitation of this vulnerability can cause a division by zero error, which may lead to a system crash or other unintended behavior.

Reproduction

The vulnerability can be reproduced by bringing the network port down, which releases the queue and sets the ring length to zero. In this state, the hbg_get_queue_used_num() function is called, triggering the division by zero error.

Remediation

The vulnerability has been addressed in the Linux kernel. Users can apply the latest patches available in the Linux kernel stable tree to mitigate this issue.

Added: Sep 4, 2025, 4:22 PM
Updated: Sep 4, 2025, 4:22 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.7
remediation
7.7
relevance
0.5
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.