cbcvebase.
CVE-2024-35826
published 2024-05-17

CVE-2024-35826: In the Linux kernel, the following vulnerability has been resolved: block: Fix page refcounts for unaligned buffers in __bio_release_pages() Fix an incorrect…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.3th percentile
In the Linux kernel, the following vulnerability has been resolved: block: Fix page refcounts for unaligned buffers in __bio_release_pages() Fix an incorrect number of pages being released for buffers that do not start at the beginning of a page.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 1b151e2435fc3a9b10c8946c6aebe9f3e1938c55 < c9d3d2fbde9b8197bce88abcbe8ee8e713ffe7c2c9d3d2fbde9b8197bce88abcbe8ee8e713ffe7c2
linuxlinux>= 1b151e2435fc3a9b10c8946c6aebe9f3e1938c55 < 38b43539d64b2fa020b3b9a752a986769f87f7a638b43539d64b2fa020b3b9a752a986769f87f7a6
linuxlinux>= 4.19.307 < 4.204.20
linuxlinux>= 5.10.210 < 5.115.11
linuxlinux>= 5.15.148 < 5.165.16
linuxlinux>= 5.4.269 < 5.55.5
linuxlinux>= 6.1.75 < 6.1.846.1.84
linuxlinux>= 6.6.14 < 6.6.246.6.24
linuxlinux>= 6.7.2 < 6.7.126.7.12
linuxlinux>= 8955324cc9f93304efe163120038b38c36c09fba < 7d3765550374f71248c55e6206ea1d6fd4537e657d3765550374f71248c55e6206ea1d6fd4537e65
linuxlinux>= 9025ee1079291fac79c7fcc20086e9f0015f86f4 < 242006996d15f5ca62e22f8c7de077d9c4a8f367242006996d15f5ca62e22f8c7de077d9c4a8f367
linuxlinux>= d198c15d181cc9d580f0f2c25150b077d1d49c1a < ecbd9ced84dd655a8f4cd49d2aad0e80dbf6bf35ecbd9ced84dd655a8f4cd49d2aad0e80dbf6bf35
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 4.19.307 < 4.204.20
linuxlinux_kernel>= 5.10.210 < 5.115.11
linuxlinux_kernel>= 5.15.148 < 5.165.16

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_msrc6.6MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.