CVE-2024-35935 — Information Exposure via Error Message in Linux
Severity
3.3LOWNVD
OSV7.0OSV6.8OSV5.5
EPSS
0.0%
top 95.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 19
Latest updateSep 18
Description
In the Linux kernel, the following vulnerability has been resolved:
btrfs: send: handle path ref underflow in header iterate_inode_ref()
Change BUG_ON to proper error handling if building the path buffer
fails. The pointers are not printed so we don't accidentally leak kernel
addresses.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4
Affected Packages5 packages
▶CVEListV5linux/linux31db9f7c23fbf7e95026143f79645de6507b583b — be2b6bcc936ae17f42fff6494106a5660b35d8d3+8
Also affects: Debian Linux 10.0
Patches
🔴Vulnerability Details
19📋Vendor Advisories
19💬Community
1Bugzilla▶
CVE-2024-35935 kernel: btrfs: send: handle path ref underflow in header iterate_inode_ref()↗2024-05-20