cbcvebase.
CVE-2024-35988
published 2024-05-20

CVE-2024-35988: In the Linux kernel, the following vulnerability has been resolved: riscv: Fix TASK_SIZE on 64-bit NOMMU On NOMMU, userspace memory can come from anywhere in…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.6th percentile
In the Linux kernel, the following vulnerability has been resolved: riscv: Fix TASK_SIZE on 64-bit NOMMU On NOMMU, userspace memory can come from anywhere in physical RAM. The current definition of TASK_SIZE is wrong if any RAM exists above 4G, causing spurious failures in the userspace access routines.

Affected

21 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.90-1 (bookworm)linux 6.1.90-1 (bookworm)
linuxlinux
linuxlinux>= 6bd33e1ece528f67646db33bf97406b747dafda0 < 04bf2e5f95c1a52e28a7567a507f926efe31c3b604bf2e5f95c1a52e28a7567a507f926efe31c3b6
linuxlinux>= 6bd33e1ece528f67646db33bf97406b747dafda0 < 52e8a42b11078d2aad4b9ba96503d77c7299168b52e8a42b11078d2aad4b9ba96503d77c7299168b
linuxlinux>= 6bd33e1ece528f67646db33bf97406b747dafda0 < 4201b8c8f2c32af321fb50867e68ac6c1cbed4be4201b8c8f2c32af321fb50867e68ac6c1cbed4be
linuxlinux>= 6bd33e1ece528f67646db33bf97406b747dafda0 < a0f0dbbb1bc49fa0de18e92c36492ff6d804cdaaa0f0dbbb1bc49fa0de18e92c36492ff6d804cdaa
linuxlinux>= 6bd33e1ece528f67646db33bf97406b747dafda0 < efdcfa554b6eb228943ef1dd4d023c606be647d2efdcfa554b6eb228943ef1dd4d023c606be647d2
linuxlinux>= 6bd33e1ece528f67646db33bf97406b747dafda0 < 6065e736f82c817c9a597a31ee67f0ce4628e9486065e736f82c817c9a597a31ee67f0ce4628e948
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.90-16.1.90-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 5.11 < 5.15.1585.15.158
linuxlinux_kernel>= 5.16 < 6.1.906.1.90
linuxlinux_kernel>= 5.5 < 5.10.2165.10.216
linuxlinux_kernel>= 6.2 < 6.6.306.6.30
linuxlinux_kernel>= 6.7 < 6.8.96.8.9

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.