CVE-2024-35854 — Use After Free in Linux
Severity
8.8HIGHNVD
OSV7.0OSV6.5OSV5.5
EPSS
0.2%
top 58.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 17
Latest updateSep 18
Description
In the Linux kernel, the following vulnerability has been resolved:
mlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash
The rehash delayed work migrates filters from one region to another
according to the number of available credits.
The migrated from region is destroyed at the end of the work if the
number of credits is non-negative as the assumption is that this is
indicative of migration being complete. This assumption is incorrect as
a non-negative number of credits can al…
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages7 packages
▶CVEListV5linux/linuxc9c9af91f1d9a636aecc55302c792538e549a430 — e118e7ea24d1392878ef85926627c6bc640c4388+7
Also affects: Debian Linux 10.0
Patches
🔴Vulnerability Details
20📋Vendor Advisories
20💬Community
1Bugzilla▶
CVE-2024-35854 kernel: mlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash↗2024-05-18