Impact
A missing zero check in the scd30 driver’s write_raw function causes a division by zero when a user writes a zero fractional part to the sampling_frequency sysfs attribute. This flaw, identified as CWE-369 (division by zero), can compromise system availability by potentially triggering a kernel panic.
Affected Systems
Linux kernel builds that include the scd30 driver and expose the sampling_frequency sysfs attribute are affected. Any system running an unpatched driver could be impacted.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog. The flaw is likely to be exploited locally by a user with write access to the sampling_frequency attribute, representing a local, permission‑restricted attack vector. Although the exploitation probability is low, the impact of a kernel crash is severe, making the overall risk noteworthy for environments where the sensor is continually accessed.
OpenCVE Enrichment
Ubuntu USN