CVE-2024-35958Linux vulnerability

46 documents7 sources
Severity
5.5MEDIUMNVD
OSV6.8
EPSS
0.0%
top 91.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 20
Latest updateMay 28

Description

In the Linux kernel, the following vulnerability has been resolved: net: ena: Fix incorrect descriptor free behavior ENA has two types of TX queues: - queues which only process TX packets arriving from the network stack - queues which only process TX packets forwarded to it by XDP_REDIRECT or XDP_TX instructions The ena_free_tx_bufs() cycles through all descriptors in a TX queue and unmaps + frees every descriptor that hasn't been acknowledged yet by the device (uncompleted TX transactions).

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDlinux/linux_kernel5.65.10.216+5
Debianlinux/linux_kernel< 5.10.216-1+3
Ubuntulinux/linux_kernel< 5.4.0-214.234+2
CVEListV5linux/linux548c4940b9f1f527f81509468dd60b61418880b6b26aa765f7437e1bbe8db4c1641b12bd5dd378f0+6
debiandebian/linux< linux 6.1.90-1 (bookworm)

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

22
OSV
linux-raspi-5.4 vulnerabilities2025-05-28
OSV
linux-raspi vulnerabilities2025-05-28
OSV
linux-xilinx-zynqmp vulnerabilities2025-05-02
OSV
linux-aws, linux-aws-5.4, linux-gcp-5.4, linux-iot vulnerabilities2025-04-24
OSV
linux-aws-fips vulnerabilities2025-04-24

📋Vendor Advisories

22
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2025-05-28
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2025-05-28
Ubuntu
Linux kernel (Xilinx ZynqMP) vulnerabilities2025-05-02
Ubuntu
Linux kernel (FIPS) vulnerabilities2025-04-24
Ubuntu
Linux kernel vulnerabilities2025-04-24

💬Community

1
Bugzilla
CVE-2024-35958 kernel: net: ena: Fix incorrect descriptor free behavior2024-05-20