cbcvebase.
CVE-2024-35830
published 2024-05-17

CVE-2024-35830: In the Linux kernel, the following vulnerability has been resolved: media: tc358743: register v4l2 async device only after successful setup Ensure the device…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
14.1th percentile
In the Linux kernel, the following vulnerability has been resolved: media: tc358743: register v4l2 async device only after successful setup Ensure the device has been setup correctly before registering the v4l2 async device, thus allowing userspace to access.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 4c5211a100399c3823563193dd881dcb3b7d24fc < 17c2650de14842c25c569cbb2126c421489a3a2417c2650de14842c25c569cbb2126c421489a3a24
linuxlinux>= 4c5211a100399c3823563193dd881dcb3b7d24fc < daf21394f9898fb9f0698c3e50de08132d2164e6daf21394f9898fb9f0698c3e50de08132d2164e6
linuxlinux>= 4c5211a100399c3823563193dd881dcb3b7d24fc < 610f20e5cf35ca9c0992693cae0dd8643ce932e7610f20e5cf35ca9c0992693cae0dd8643ce932e7
linuxlinux>= 4c5211a100399c3823563193dd881dcb3b7d24fc < b8505a1aee8f1edc9d16d72ae09c93de086e2a1ab8505a1aee8f1edc9d16d72ae09c93de086e2a1a
linuxlinux>= 4c5211a100399c3823563193dd881dcb3b7d24fc < 8ba8db9786b55047df5ad3db3e01dd886687a77d8ba8db9786b55047df5ad3db3e01dd886687a77d
linuxlinux>= 4c5211a100399c3823563193dd881dcb3b7d24fc < edbb3226c985469a2f8eb69885055c9f5550f468edbb3226c985469a2f8eb69885055c9f5550f468
linuxlinux>= 4c5211a100399c3823563193dd881dcb3b7d24fc < c915c46a25c3efb084c4f5e69a053d7f7a635496c915c46a25c3efb084c4f5e69a053d7f7a635496
linuxlinux>= 4c5211a100399c3823563193dd881dcb3b7d24fc < 4f1490a5d7a0472ee5d9f36547bc4ba46be755c74f1490a5d7a0472ee5d9f36547bc4ba46be755c7
linuxlinux>= 4c5211a100399c3823563193dd881dcb3b7d24fc < 87399f1ff92203d65f1febf5919429f4bb613a0287399f1ff92203d65f1febf5919429f4bb613a02
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 4.20 < 5.4.2735.4.273
linuxlinux_kernel>= 4.3 < 4.19.3114.19.311
linuxlinux_kernel>= 5.11 < 5.15.1535.15.153
linuxlinux_kernel>= 5.16 < 6.1.836.1.83
linuxlinux_kernel>= 5.5 < 5.10.2145.10.214
linuxlinux_kernel>= 6.2 < 6.6.236.6.23

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.