CVE-2024-35971 (GCVE-0-2024-35971)
Vulnerability from cvelistv5
Published
2024-05-20 09:41
Modified
2026-08-05 11:31
Summary
In the Linux kernel, the following vulnerability has been resolved: net: ks8851: Handle softirqs at the end of IRQ thread to fix hang The ks8851_irq() thread may call ks8851_rx_pkts() in case there are any packets in the MAC FIFO, which calls netif_rx(). This netif_rx() implementation is guarded by local_bh_disable() and local_bh_enable(). The local_bh_enable() may call do_softirq() to run softirqs in case any are pending. One of the softirqs is net_rx_action, which ultimately reaches the driver .start_xmit callback. If that happens, the system hangs. The entire call chain is below: ks8851_start_xmit_par from netdev_start_xmit netdev_start_xmit from dev_hard_start_xmit dev_hard_start_xmit from sch_direct_xmit sch_direct_xmit from __dev_queue_xmit __dev_queue_xmit from __neigh_update __neigh_update from neigh_update neigh_update from arp_process.constprop.0 arp_process.constprop.0 from __netif_receive_skb_one_core __netif_receive_skb_one_core from process_backlog process_backlog from __napi_poll.constprop.0 __napi_poll.constprop.0 from net_rx_action net_rx_action from __do_softirq __do_softirq from call_with_stack call_with_stack from do_softirq do_softirq from __local_bh_enable_ip __local_bh_enable_ip from netif_rx netif_rx from ks8851_irq ks8851_irq from irq_thread_fn irq_thread_fn from irq_thread irq_thread from kthread kthread from ret_from_fork The hang happens because ks8851_irq() first locks a spinlock in ks8851_par.c ks8851_lock_par() spin_lock_irqsave(&ksp->lock, ...) and with that spinlock locked, calls netif_rx(). Once the execution reaches ks8851_start_xmit_par(), it calls ks8851_lock_par() again which attempts to claim the already locked spinlock again, and the hang happens. Move the do_softirq() call outside of the spinlock protected section of ks8851_irq() by disabling BHs around the entire spinlock protected section of ks8851_irq() handler. Place local_bh_enable() outside of the spinlock protected section, so that it can trigger do_softirq() without the ks8851_par.c ks8851_lock_par() spinlock being held, and safely call ks8851_start_xmit_par() without attempting to lock the already locked spinlock. Since ks8851_irq() is protected by local_bh_disable()/local_bh_enable() now, replace netif_rx() with __netif_rx() which is not duplicating the local_bh_disable()/local_bh_enable() calls.
Impacted products
Vendor Product Version
Linux Linux Version: 797047f875b5463719cc70ba213eb691d453c946
Version: 797047f875b5463719cc70ba213eb691d453c946
Version: 797047f875b5463719cc70ba213eb691d453c946
Version: 797047f875b5463719cc70ba213eb691d453c946
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-35971",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-05-20T15:04:05.232058Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-06-04T17:33:27.183Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T03:21:49.046Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/492337a4fbd1421b42df684ee9b34be2a2722540"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/cba376eb036c2c20077b41d47b317d8218fe754f"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/49d5d70538b6b8f2a3f8f1ac30c1f921d4a0929b"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/be0384bf599cf1eb8d337517feeb732d71f75a6f"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "http://www.openwall.com/lists/oss-security/2024/05/30/2"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "http://www.openwall.com/lists/oss-security/2024/05/30/1"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/micrel/ks8851_common.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "492337a4fbd1421b42df684ee9b34be2a2722540",
              "status": "affected",
              "version": "797047f875b5463719cc70ba213eb691d453c946",
              "versionType": "git"
            },
            {
              "lessThan": "cba376eb036c2c20077b41d47b317d8218fe754f",
              "status": "affected",
              "version": "797047f875b5463719cc70ba213eb691d453c946",
              "versionType": "git"
            },
            {
              "lessThan": "49d5d70538b6b8f2a3f8f1ac30c1f921d4a0929b",
              "status": "affected",
              "version": "797047f875b5463719cc70ba213eb691d453c946",
              "versionType": "git"
            },
            {
              "lessThan": "be0384bf599cf1eb8d337517feeb732d71f75a6f",
              "status": "affected",
              "version": "797047f875b5463719cc70ba213eb691d453c946",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/micrel/ks8851_common.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.8"
            },
            {
              "lessThan": "5.8",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.87",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.28",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.8.*",
              "status": "unaffected",
              "version": "6.8.7",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.9",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.87",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.28",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8.7",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.9",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ks8851: Handle softirqs at the end of IRQ thread to fix hang\n\nThe ks8851_irq() thread may call ks8851_rx_pkts() in case there are\nany packets in the MAC FIFO, which calls netif_rx(). This netif_rx()\nimplementation is guarded by local_bh_disable() and local_bh_enable().\nThe local_bh_enable() may call do_softirq() to run softirqs in case\nany are pending. One of the softirqs is net_rx_action, which ultimately\nreaches the driver .start_xmit callback. If that happens, the system\nhangs. The entire call chain is below:\n\nks8851_start_xmit_par from netdev_start_xmit\nnetdev_start_xmit from dev_hard_start_xmit\ndev_hard_start_xmit from sch_direct_xmit\nsch_direct_xmit from __dev_queue_xmit\n__dev_queue_xmit from __neigh_update\n__neigh_update from neigh_update\nneigh_update from arp_process.constprop.0\narp_process.constprop.0 from __netif_receive_skb_one_core\n__netif_receive_skb_one_core from process_backlog\nprocess_backlog from __napi_poll.constprop.0\n__napi_poll.constprop.0 from net_rx_action\nnet_rx_action from __do_softirq\n__do_softirq from call_with_stack\ncall_with_stack from do_softirq\ndo_softirq from __local_bh_enable_ip\n__local_bh_enable_ip from netif_rx\nnetif_rx from ks8851_irq\nks8851_irq from irq_thread_fn\nirq_thread_fn from irq_thread\nirq_thread from kthread\nkthread from ret_from_fork\n\nThe hang happens because ks8851_irq() first locks a spinlock in\nks8851_par.c ks8851_lock_par() spin_lock_irqsave(\u0026ksp-\u003elock, ...)\nand with that spinlock locked, calls netif_rx(). Once the execution\nreaches ks8851_start_xmit_par(), it calls ks8851_lock_par() again\nwhich attempts to claim the already locked spinlock again, and the\nhang happens.\n\nMove the do_softirq() call outside of the spinlock protected section\nof ks8851_irq() by disabling BHs around the entire spinlock protected\nsection of ks8851_irq() handler. Place local_bh_enable() outside of\nthe spinlock protected section, so that it can trigger do_softirq()\nwithout the ks8851_par.c ks8851_lock_par() spinlock being held, and\nsafely call ks8851_start_xmit_par() without attempting to lock the\nalready locked spinlock.\n\nSince ks8851_irq() is protected by local_bh_disable()/local_bh_enable()\nnow, replace netif_rx() with __netif_rx() which is not duplicating the\nlocal_bh_disable()/local_bh_enable() calls."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The deadlock is triggered purely by a received Ethernet frame whose RX processing emits an immediate reply in softirq context \u2014 ICMP echo requests, TCP SYNs eliciting SYN-ACKs, and forwarded traffic all do this and are routable from an arbitrary remote host, not just the local segment. Per net/ stack guidance, bugs reachable via received packets are Network.\nAC:L - The attacker fully controls the trigger by sending a single packet that elicits a reply (ping, ARP request, TCP SYN); no race, memory layout, or victim state is involved, and the hang even occurs under ordinary legitimate traffic.\nPR:N - The vulnerable code runs in the NIC\u0027s threaded IRQ handler on raw packet reception, entirely before any socket, authentication, or authorization check \u2014 an unauthenticated remote attacker needs no credentials on the target.\nUI:N - No victim action is required; the packet is processed automatically by the driver\u0027s interrupt thread as soon as it arrives on the wire.\nS:U - The recursive spinlock acquisition deadlocks the kernel itself, with no crossing of a virtualization, IOMMU, or sandbox boundary \u2014 impact stays within the same security authority.\nC:N - The bug is a lock-recursion deadlock with no out-of-bounds access, no use-after-free, and no leaked data; the fix only reorders BH handling and switches to __netif_rx(), confirming no information is exposed.\nI:N - No memory is corrupted and no data is modified \u2014 the CPU simply spins forever on a lock it already holds, giving no write primitive of any kind.\nA:H - Re-acquiring the non-recursive spinlock taken with spin_lock_irqsave() wedges the CPU with local interrupts disabled, producing a full system hang (unrecoverable without watchdog reset on the typical single-core embedded boards using the KS8851 parallel bus)."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:31:19.610Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/492337a4fbd1421b42df684ee9b34be2a2722540"
        },
        {
          "url": "https://git.kernel.org/stable/c/cba376eb036c2c20077b41d47b317d8218fe754f"
        },
        {
          "url": "https://git.kernel.org/stable/c/49d5d70538b6b8f2a3f8f1ac30c1f921d4a0929b"
        },
        {
          "url": "https://git.kernel.org/stable/c/be0384bf599cf1eb8d337517feeb732d71f75a6f"
        }
      ],
      "title": "net: ks8851: Handle softirqs at the end of IRQ thread to fix hang",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-35971",
    "datePublished": "2024-05-20T09:41:59.174Z",
    "dateReserved": "2024-05-17T13:50:33.141Z",
    "dateUpdated": "2026-08-05T11:31:19.610Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/492337a4fbd1421b42df684ee9b34be2a2722540\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/cba376eb036c2c20077b41d47b317d8218fe754f\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/49d5d70538b6b8f2a3f8f1ac30c1f921d4a0929b\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/be0384bf599cf1eb8d337517feeb732d71f75a6f\", \"tags\": [\"x_transferred\"]}, {\"url\": \"http://www.openwall.com/lists/oss-security/2024/05/30/2\", \"tags\": [\"x_transferred\"]}, {\"url\": \"http://www.openwall.com/lists/oss-security/2024/05/30/1\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T03:21:49.046Z\"}}, {\"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-35971\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-05-20T15:04:05.232058Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-05-23T19:01:24.904Z\"}, \"title\": \"CISA ADP Vulnrichment\"}], \"cna\": {\"title\": \"net: ks8851: Handle softirqs at the end of IRQ thread to fix hang\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.5, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:N - The deadlock is triggered purely by a received Ethernet frame whose RX processing emits an immediate reply in softirq context \\u2014 ICMP echo requests, TCP SYNs eliciting SYN-ACKs, and forwarded traffic all do this and are routable from an arbitrary remote host, not just the local segment. Per net/ stack guidance, bugs reachable via received packets are Network.\\nAC:L - The attacker fully controls the trigger by sending a single packet that elicits a reply (ping, ARP request, TCP SYN); no race, memory layout, or victim state is involved, and the hang even occurs under ordinary legitimate traffic.\\nPR:N - The vulnerable code runs in the NIC\u0027s threaded IRQ handler on raw packet reception, entirely before any socket, authentication, or authorization check \\u2014 an unauthenticated remote attacker needs no credentials on the target.\\nUI:N - No victim action is required; the packet is processed automatically by the driver\u0027s interrupt thread as soon as it arrives on the wire.\\nS:U - The recursive spinlock acquisition deadlocks the kernel itself, with no crossing of a virtualization, IOMMU, or sandbox boundary \\u2014 impact stays within the same security authority.\\nC:N - The bug is a lock-recursion deadlock with no out-of-bounds access, no use-after-free, and no leaked data; the fix only reorders BH handling and switches to __netif_rx(), confirming no information is exposed.\\nI:N - No memory is corrupted and no data is modified \\u2014 the CPU simply spins forever on a lock it already holds, giving no write primitive of any kind.\\nA:H - Re-acquiring the non-recursive spinlock taken with spin_lock_irqsave() wedges the CPU with local interrupts disabled, producing a full system hang (unrecoverable without watchdog reset on the typical single-core embedded boards using the KS8851 parallel bus).\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"797047f875b5463719cc70ba213eb691d453c946\", \"lessThan\": \"492337a4fbd1421b42df684ee9b34be2a2722540\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"797047f875b5463719cc70ba213eb691d453c946\", \"lessThan\": \"cba376eb036c2c20077b41d47b317d8218fe754f\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"797047f875b5463719cc70ba213eb691d453c946\", \"lessThan\": \"49d5d70538b6b8f2a3f8f1ac30c1f921d4a0929b\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"797047f875b5463719cc70ba213eb691d453c946\", \"lessThan\": \"be0384bf599cf1eb8d337517feeb732d71f75a6f\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/net/ethernet/micrel/ks8851_common.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.8\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.8\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.1.87\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.28\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8.7\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.8.*\"}, {\"status\": \"unaffected\", \"version\": \"6.9\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/net/ethernet/micrel/ks8851_common.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/492337a4fbd1421b42df684ee9b34be2a2722540\"}, {\"url\": \"https://git.kernel.org/stable/c/cba376eb036c2c20077b41d47b317d8218fe754f\"}, {\"url\": \"https://git.kernel.org/stable/c/49d5d70538b6b8f2a3f8f1ac30c1f921d4a0929b\"}, {\"url\": \"https://git.kernel.org/stable/c/be0384bf599cf1eb8d337517feeb732d71f75a6f\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nnet: ks8851: Handle softirqs at the end of IRQ thread to fix hang\\n\\nThe ks8851_irq() thread may call ks8851_rx_pkts() in case there are\\nany packets in the MAC FIFO, which calls netif_rx(). This netif_rx()\\nimplementation is guarded by local_bh_disable() and local_bh_enable().\\nThe local_bh_enable() may call do_softirq() to run softirqs in case\\nany are pending. One of the softirqs is net_rx_action, which ultimately\\nreaches the driver .start_xmit callback. If that happens, the system\\nhangs. The entire call chain is below:\\n\\nks8851_start_xmit_par from netdev_start_xmit\\nnetdev_start_xmit from dev_hard_start_xmit\\ndev_hard_start_xmit from sch_direct_xmit\\nsch_direct_xmit from __dev_queue_xmit\\n__dev_queue_xmit from __neigh_update\\n__neigh_update from neigh_update\\nneigh_update from arp_process.constprop.0\\narp_process.constprop.0 from __netif_receive_skb_one_core\\n__netif_receive_skb_one_core from process_backlog\\nprocess_backlog from __napi_poll.constprop.0\\n__napi_poll.constprop.0 from net_rx_action\\nnet_rx_action from __do_softirq\\n__do_softirq from call_with_stack\\ncall_with_stack from do_softirq\\ndo_softirq from __local_bh_enable_ip\\n__local_bh_enable_ip from netif_rx\\nnetif_rx from ks8851_irq\\nks8851_irq from irq_thread_fn\\nirq_thread_fn from irq_thread\\nirq_thread from kthread\\nkthread from ret_from_fork\\n\\nThe hang happens because ks8851_irq() first locks a spinlock in\\nks8851_par.c ks8851_lock_par() spin_lock_irqsave(\u0026ksp-\u003elock, ...)\\nand with that spinlock locked, calls netif_rx(). Once the execution\\nreaches ks8851_start_xmit_par(), it calls ks8851_lock_par() again\\nwhich attempts to claim the already locked spinlock again, and the\\nhang happens.\\n\\nMove the do_softirq() call outside of the spinlock protected section\\nof ks8851_irq() by disabling BHs around the entire spinlock protected\\nsection of ks8851_irq() handler. Place local_bh_enable() outside of\\nthe spinlock protected section, so that it can trigger do_softirq()\\nwithout the ks8851_par.c ks8851_lock_par() spinlock being held, and\\nsafely call ks8851_start_xmit_par() without attempting to lock the\\nalready locked spinlock.\\n\\nSince ks8851_irq() is protected by local_bh_disable()/local_bh_enable()\\nnow, replace netif_rx() with __netif_rx() which is not duplicating the\\nlocal_bh_disable()/local_bh_enable() calls.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.87\", \"versionStartIncluding\": \"5.8\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.28\", \"versionStartIncluding\": \"5.8\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8.7\", \"versionStartIncluding\": \"5.8\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.9\", \"versionStartIncluding\": \"5.8\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:31:19.610Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-35971\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:31:19.610Z\", \"dateReserved\": \"2024-05-17T13:50:33.141Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-05-20T09:41:59.174Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…