cbcvebase.
CVE-2024-35847
published 2024-05-17

CVE-2024-35847: In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Prevent double free on error The error handling path in…

PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.8th percentile
In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Prevent double free on error The error handling path in its_vpe_irq_domain_alloc() causes a double free when its_vpe_init() fails after successfully allocating at least one interrupt. This happens because its_vpe_irq_domain_free() frees the interrupts along with the area bitmap and the vprop_page and its_vpe_irq_domain_alloc() subsequently frees the area bitmap and the vprop_page again. Fix this by unconditionally invoking its_vpe_irq_domain_free() which handles all cases correctly and by removing the bitmap/vprop_page freeing from its_vpe_irq_domain_alloc(). [ tglx: Massaged change log ]

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.90-1 (bookworm)linux 6.1.90-1 (bookworm)
linuxlinux
linuxlinux>= 7d75bbb4bc1ad90386776459d37e4ddfe605671e < f5417ff561b8ac9a7e53c747b8627a7ab58378aef5417ff561b8ac9a7e53c747b8627a7ab58378ae
linuxlinux>= 7d75bbb4bc1ad90386776459d37e4ddfe605671e < b72d2b1448b682844f995e660b77f2a1fabc1662b72d2b1448b682844f995e660b77f2a1fabc1662
linuxlinux>= 7d75bbb4bc1ad90386776459d37e4ddfe605671e < aa44d21574751a7d6bca892eb8e0e9ac68372e52aa44d21574751a7d6bca892eb8e0e9ac68372e52
linuxlinux>= 7d75bbb4bc1ad90386776459d37e4ddfe605671e < 5dbdbe1133911ca7d8466bb86885adec32ad94385dbdbe1133911ca7d8466bb86885adec32ad9438
linuxlinux>= 7d75bbb4bc1ad90386776459d37e4ddfe605671e < dd681710ab77c8beafe2e263064cb1bd0e2d6ca9dd681710ab77c8beafe2e263064cb1bd0e2d6ca9
linuxlinux>= 7d75bbb4bc1ad90386776459d37e4ddfe605671e < 03170e657f62c26834172742492a8cb8077ef79203170e657f62c26834172742492a8cb8077ef792
linuxlinux>= 7d75bbb4bc1ad90386776459d37e4ddfe605671e < 5b012f77abde89bf0be8a0547636184fea6181375b012f77abde89bf0be8a0547636184fea618137
linuxlinux>= 7d75bbb4bc1ad90386776459d37e4ddfe605671e < c26591afd33adce296c022e3480dea4282b7ef91c26591afd33adce296c022e3480dea4282b7ef91
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.90-16.1.90-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 0 < 4.15.0-232.2444.15.0-232.244
linuxlinux_kernel>= 4.14 < 4.19.3134.19.313
linuxlinux_kernel>= 4.20 < 5.4.2755.4.275
linuxlinux_kernel>= 5.11 < 5.15.1585.15.158
linuxlinux_kernel>= 5.16 < 6.1.906.1.90
linuxlinux_kernel>= 5.5 < 5.10.2165.10.216

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.