cbcvebase.
CVE-2024-35983
published 2024-05-20

CVE-2024-35983: In the Linux kernel, the following vulnerability has been resolved: bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS bits_per() rounds up…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.6th percentile
In the Linux kernel, the following vulnerability has been resolved: bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS bits_per() rounds up to the next power of two when passed a power of two. This causes crashes on some machines and configurations.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.90-1 (bookworm)linux 6.1.90-1 (bookworm)
linuxlinux
linuxlinux>= 428ca0000f0abd5c99354c52a36becf2b815ca21 < 9b7c5004d7c5ae062134052a85290869a015814c9b7c5004d7c5ae062134052a85290869a015814c
linuxlinux>= 5.10.215 < 5.10.2165.10.216
linuxlinux>= 5.15.154 < 5.15.1585.15.158
linuxlinux>= 5.4.274 < 5.4.2755.4.275
linuxlinux>= 6.1.84 < 6.1.906.1.90
linuxlinux>= 6.6.24 < 6.6.306.6.30
linuxlinux>= 6.7.12 < 6.86.8
linuxlinux>= 6.8.3 < 6.8.96.8.9
linuxlinux>= 83a2275f9d3230c761014b1467888b1ef469be74 < 66297b2ceda841f809637731d287bda3a93b49d866297b2ceda841f809637731d287bda3a93b49d8
linuxlinux>= b46c822f8b555b9513df44047b0e72c06720df62 < 15aa09d6d84629eb5296de30ac0aa19a33512f1615aa09d6d84629eb5296de30ac0aa19a33512f16
linuxlinux>= cf778fff03be1ee88c49b72959650147573c3301 < ebfe41889b762f1933c6762f6624b9724a25bee0ebfe41889b762f1933c6762f6624b9724a25bee0
linuxlinux>= d2a7a81088c6abe778b0a93a7eeb79487a943818 < 93ba36238db6a74a82feb3dc476e25ea424ad63093ba36238db6a74a82feb3dc476e25ea424ad630
linuxlinux>= d6077e0d38b4953c863d0db4a5b3f41d21e0d546 < d34a516f2635090d36a306f84573e8de3d7374ced34a516f2635090d36a306f84573e8de3d7374ce
linuxlinux>= f2d5dcb48f7ba9e3ff249d58fc1fa963d374e66a < 5af385f5f4cddf908f663974847a4083b2ff2c795af385f5f4cddf908f663974847a4083b2ff2c79
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.90-16.1.90-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 5.10.215 < 5.10.2165.10.216
linuxlinux_kernel>= 5.15.154 < 5.15.1585.15.158
linuxlinux_kernel>= 5.4.274 < 5.4.2755.4.275
linuxlinux_kernel>= 6.1.84 < 6.1.906.1.90

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.