CVE-2024-35871 — Linux vulnerability
30 documents7 sources
Severity
7.1HIGHNVD
OSV6.8OSV5.5
EPSS
0.0%
top 98.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 19
Latest updateSep 18
Description
In the Linux kernel, the following vulnerability has been resolved:
riscv: process: Fix kernel gp leakage
childregs represents the registers which are active for the new thread
in user context. For a kernel thread, childregs->gp is never used since
the kernel gp is not touched by switch_to. For a user mode helper, the
gp value can be observed in user space after execve or possibly by other
means.
[From the email thread]
The /* Kernel thread */ comment is somewhat inaccurate in that it is als…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2
Affected Packages5 packages
▶CVEListV5linux/linux7db91e57a0acde126a162ababfb1e0ab190130cb — 9abc3e6f1116adb7a2d4fbb8ce20c37916976bf5+6
Also affects: Debian Linux 10.0