cbcvebase.
CVE-2024-35935
published 2024-05-19

CVE-2024-35935: In the Linux kernel, the following vulnerability has been resolved: btrfs: send: handle path ref underflow in header iterate_inode_ref() Change BUG_ON to…

PriorityP49low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.22%
13.0th percentile
In the Linux kernel, the following vulnerability has been resolved: btrfs: send: handle path ref underflow in header iterate_inode_ref() Change BUG_ON to proper error handling if building the path buffer fails. The pointers are not printed so we don't accidentally leak kernel addresses.

Affected

25 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.90-1 (bookworm)linux 6.1.90-1 (bookworm)
linuxlinux
linuxlinux>= 31db9f7c23fbf7e95026143f79645de6507b583b < be2b6bcc936ae17f42fff6494106a5660b35d8d3be2b6bcc936ae17f42fff6494106a5660b35d8d3
linuxlinux>= 31db9f7c23fbf7e95026143f79645de6507b583b < 024529c27c8b4b273325a169e078337c8279e229024529c27c8b4b273325a169e078337c8279e229
linuxlinux>= 31db9f7c23fbf7e95026143f79645de6507b583b < 4720d590c4cb5d9ffa0060b89743651cc7e995f94720d590c4cb5d9ffa0060b89743651cc7e995f9
linuxlinux>= 31db9f7c23fbf7e95026143f79645de6507b583b < 2f6174fd4ccf403b42b3d5f0d1b6b496a0e5330a2f6174fd4ccf403b42b3d5f0d1b6b496a0e5330a
linuxlinux>= 31db9f7c23fbf7e95026143f79645de6507b583b < 9ae356c627b493323e1433dcb27a26917668c07c9ae356c627b493323e1433dcb27a26917668c07c
linuxlinux>= 31db9f7c23fbf7e95026143f79645de6507b583b < c1363ed8867b81ea169fba2ccc14af96a85ed183c1363ed8867b81ea169fba2ccc14af96a85ed183
linuxlinux>= 31db9f7c23fbf7e95026143f79645de6507b583b < 03938619a1e718b6168ae4528e1b0f979293f1a503938619a1e718b6168ae4528e1b0f979293f1a5
linuxlinux>= 31db9f7c23fbf7e95026143f79645de6507b583b < 3c6ee34c6f9cd12802326da26631232a617435013c6ee34c6f9cd12802326da26631232a61743501
linuxlinux_kernel< 4.19.3124.19.312
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.90-16.1.90-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-38.386.8.0-38.38
linuxlinux_kernel>= 4.20 < 5.4.2745.4.274
linuxlinux_kernel>= 5.11 < 5.15.1555.15.155
linuxlinux_kernel>= 5.16 < 6.1.866.1.86
linuxlinux_kernel>= 5.5 < 5.10.2155.10.215
linuxlinux_kernel>= 6.2 < 6.6.276.6.27
linuxlinux_kernel>= 6.7 < 6.8.66.8.6

CVSS provenance

nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.