cbcvebase.
CVE-2024-35800
published 2024-05-17

CVE-2024-35800: In the Linux kernel, the following vulnerability has been resolved: efi: fix panic in kdump kernel Check if get_next_variable() is actually valid pointer…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.2th percentile
In the Linux kernel, the following vulnerability has been resolved: efi: fix panic in kdump kernel Check if get_next_variable() is actually valid pointer before calling it. In kdump kernel this method is set to NULL that causes panic during the kexec-ed kernel boot. Tested with QEMU and OVMF firmware.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 6.1.81 < 6.1.846.1.84
linuxlinux>= a8901f331b8b7f95a7315d033a22bc84c8365f35 < b9d103aca85f082a343b222493f3cab1219aaaf4b9d103aca85f082a343b222493f3cab1219aaaf4
linuxlinux>= bad267f9e18f8e9e628abd1811d2899b1735a4e1 < 9114ba9987506bcfbb454f6e68558d68cb1abbde9114ba9987506bcfbb454f6e68558d68cb1abbde
linuxlinux>= bad267f9e18f8e9e628abd1811d2899b1735a4e1 < 7784135f134c13af17d9ffb39a57db8500bc60ff7784135f134c13af17d9ffb39a57db8500bc60ff
linuxlinux>= bad267f9e18f8e9e628abd1811d2899b1735a4e1 < 090d2b4515ade379cd592fbc8931344945978210090d2b4515ade379cd592fbc8931344945978210
linuxlinux>= bad267f9e18f8e9e628abd1811d2899b1735a4e1 < 62b71cd73d41ddac6b1760402bbe8c4932e2353162b71cd73d41ddac6b1760402bbe8c4932e23531
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 6.1.81 < 6.1.846.1.84
linuxlinux_kernel>= 6.3 < 6.6.246.6.24
linuxlinux_kernel>= 6.7 < 6.7.126.7.12
linuxlinux_kernel>= 6.8 < 6.8.36.8.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.