cbcvebase.
CVE-2024-35940
published 2024-05-19

CVE-2024-35940: In the Linux kernel, the following vulnerability has been resolved: pstore/zone: Add a null pointer check to the psz_kmsg_read kasprintf() returns a pointer to…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.3th percentile
In the Linux kernel, the following vulnerability has been resolved: pstore/zone: Add a null pointer check to the psz_kmsg_read kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure. Ensure the allocation was successful by checking the pointer validity.

Affected

20 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.90-1 (bookworm)linux 6.1.90-1 (bookworm)
linuxlinux
linuxlinux>= d26c3321fe18dc74517dc1f518d584aa33b0a851 < 98e2b97acb875d65bdfc75fc408e67975cef304198e2b97acb875d65bdfc75fc408e67975cef3041
linuxlinux>= d26c3321fe18dc74517dc1f518d584aa33b0a851 < 0ff96ec22a84d80a18d7ae8ca7eb111c34ee33bb0ff96ec22a84d80a18d7ae8ca7eb111c34ee33bb
linuxlinux>= d26c3321fe18dc74517dc1f518d584aa33b0a851 < 635594cca59f9d7a8e96187600c34facb8bc0682635594cca59f9d7a8e96187600c34facb8bc0682
linuxlinux>= d26c3321fe18dc74517dc1f518d584aa33b0a851 < ec7256887d072f98c42cdbef4dcc80ddf84c7a70ec7256887d072f98c42cdbef4dcc80ddf84c7a70
linuxlinux>= d26c3321fe18dc74517dc1f518d584aa33b0a851 < 6f9f2e498eae7897ba5d3e33908917f68ff4abcc6f9f2e498eae7897ba5d3e33908917f68ff4abcc
linuxlinux>= d26c3321fe18dc74517dc1f518d584aa33b0a851 < 98bc7e26e14fbb26a6abf97603d59532475e97f898bc7e26e14fbb26a6abf97603d59532475e97f8
linuxlinux_kernel< 5.10.2155.10.215
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.90-16.1.90-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-38.386.8.0-38.38
linuxlinux_kernel>= 5.11 < 5.15.1555.15.155
linuxlinux_kernel>= 5.16 < 6.1.866.1.86
linuxlinux_kernel>= 6.2 < 6.6.276.6.27
linuxlinux_kernel>= 6.7 < 6.8.66.8.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.8MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.