cbcvebase.
CVE-2024-35915
published 2024-05-19

CVE-2024-35915: In the Linux kernel, the following vulnerability has been resolved: nfc: nci: Fix uninit-value in nci_dev_up and nci_ntf_packet syzbot reported the following…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.32%
24.4th percentile
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: Fix uninit-value in nci_dev_up and nci_ntf_packet syzbot reported the following uninit-value access issue [1][2]: nci_rx_work() parses and processes received packet. When the payload length is zero, each message type handler reads uninitialized payload and KMSAN detects this issue. The receipt of a packet with a zero-size payload is considered unexpected, and therefore, such packets should be silently discarded. This patch resolved this issue by checking payload size before calling each message type handler codes.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 6a2968aaf50c7a22fced77a5e24aa636281efca8 < 11387b2effbb55f58dc2111ef4b4b896f275624011387b2effbb55f58dc2111ef4b4b896f2756240
linuxlinux>= 6a2968aaf50c7a22fced77a5e24aa636281efca8 < 03fe259649a551d336a7f20919b641ea100e3fff03fe259649a551d336a7f20919b641ea100e3fff
linuxlinux>= 6a2968aaf50c7a22fced77a5e24aa636281efca8 < 755e53bbc61bc1aff90eafa64c8c2464fd3dfa3c755e53bbc61bc1aff90eafa64c8c2464fd3dfa3c
linuxlinux>= 6a2968aaf50c7a22fced77a5e24aa636281efca8 < ac68d9fa09e410fa3ed20fb721d56aa558695e16ac68d9fa09e410fa3ed20fb721d56aa558695e16
linuxlinux>= 6a2968aaf50c7a22fced77a5e24aa636281efca8 < b51ec7fc9f877ef869c01d3ea6f18f6a64e831a7b51ec7fc9f877ef869c01d3ea6f18f6a64e831a7
linuxlinux>= 6a2968aaf50c7a22fced77a5e24aa636281efca8 < a946ebee45b09294c8b0b0e77410b763c4d2817aa946ebee45b09294c8b0b0e77410b763c4d2817a
linuxlinux>= 6a2968aaf50c7a22fced77a5e24aa636281efca8 < 8948e30de81faee87eeee01ef42a1f6008f5a83a8948e30de81faee87eeee01ef42a1f6008f5a83a
linuxlinux>= 6a2968aaf50c7a22fced77a5e24aa636281efca8 < d24b03535e5eb82e025219c2f632b485409c898fd24b03535e5eb82e025219c2f632b485409c898f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-38.386.8.0-38.38
linuxlinux_kernel>= 3.2 < 4.19.3124.19.312
linuxlinux_kernel>= 4.20 < 5.4.2745.4.274
linuxlinux_kernel>= 5.11 < 5.15.1545.15.154
linuxlinux_kernel>= 5.16 < 6.1.856.1.85
linuxlinux_kernel>= 5.5 < 5.10.2155.10.215
linuxlinux_kernel>= 6.2 < 6.6.266.6.26

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.