cbcvebase.
CVE-2024-35984
published 2024-05-20

CVE-2024-35984: In the Linux kernel, the following vulnerability has been resolved: i2c: smbus: fix NULL function pointer dereference Baruch reported an OOPS when using the…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.3th percentile
In the Linux kernel, the following vulnerability has been resolved: i2c: smbus: fix NULL function pointer dereference Baruch reported an OOPS when using the designware controller as target only. Target-only modes break the assumption of one transfer function always being available. Fix this by always checking the pointer in __i2c_transfer. [wsa: dropped the simplification in core-smbus to avoid theoretical regressions]

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.90-1 (bookworm)linux 6.1.90-1 (bookworm)
linuxlinux
linuxlinux>= 63453b59e41173241c4efe9335815f6432fa8586 < 40f1d79f07b49c8a64a861706e5163f2db4bd95d40f1d79f07b49c8a64a861706e5163f2db4bd95d
linuxlinux>= 63453b59e41173241c4efe9335815f6432fa8586 < ad3c3ac7a03be3697114f781193dd3e9d97e6e23ad3c3ac7a03be3697114f781193dd3e9d97e6e23
linuxlinux>= 63453b59e41173241c4efe9335815f6432fa8586 < 5fd72404587d7db4acb2d241fd8c387afb0a7aec5fd72404587d7db4acb2d241fd8c387afb0a7aec
linuxlinux>= 63453b59e41173241c4efe9335815f6432fa8586 < 5a09eae9a7db597fe0c1fc91636205b4a25d26205a09eae9a7db597fe0c1fc91636205b4a25d2620
linuxlinux>= 63453b59e41173241c4efe9335815f6432fa8586 < 4e75e222d397c6752b229ed72fc4644c8c36ecde4e75e222d397c6752b229ed72fc4644c8c36ecde
linuxlinux>= 63453b59e41173241c4efe9335815f6432fa8586 < e3425674ff68dc521c57c6eabad0cbd20a027d85e3425674ff68dc521c57c6eabad0cbd20a027d85
linuxlinux>= 63453b59e41173241c4efe9335815f6432fa8586 < 357c64ef1ef39b1e7cd91ab6bdd304d043702c83357c64ef1ef39b1e7cd91ab6bdd304d043702c83
linuxlinux>= 63453b59e41173241c4efe9335815f6432fa8586 < 91811a31b68d3765b3065f4bb6d7d6d84a7cfc9f91811a31b68d3765b3065f4bb6d7d6d84a7cfc9f
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.90-16.1.90-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-39.396.8.0-39.39
linuxlinux_kernel>= 0 < 4.4.0-257.2914.4.0-257.291
linuxlinux_kernel>= 3.19 < 4.19.3134.19.313
linuxlinux_kernel>= 4.20 < 5.4.2755.4.275
linuxlinux_kernel>= 5.11 < 5.15.1585.15.158
linuxlinux_kernel>= 5.16 < 6.1.906.1.90
linuxlinux_kernel>= 5.5 < 5.10.2165.10.216
linuxlinux_kernel>= 6.2 < 6.6.306.6.30
linuxlinux_kernel>= 6.7 < 6.8.96.8.9

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.