PT-2024-26816 · Linux+6 · Linux Kernel+6

Syzbot

·

Published

2024-04-04

·

Updated

2025-09-29

·

CVE-2024-35976

CVSS v3.1

6.7

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.8.0
Description The vulnerability is related to the xsk (Express Data Path) feature in the Linux kernel. It was reported by syzbot, which detected an illegal copy in the xsk setsockopt() function. The issue arises from the failure to validate user input for XDP UMEM FILL RING and XDP COMPLETION FILL RING, leading to a slab-out-of-bounds error. This can be exploited by providing a specially crafted optlen parameter to the setsockopt() function, potentially allowing an attacker to execute arbitrary code or cause a denial-of-service condition.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for this vulnerability. Ensure that the updated kernel version validates user input for XDP UMEM FILL RING and XDP COMPLETION FILL RING to prevent slab-out-of-bounds errors. Additionally, consider implementing security measures such as input validation and error handling to prevent similar vulnerabilities in the future.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
BDU:2025-04527
CVE-2024-35976
DLA-3842-1
INFSA-2024_9315
OESA-2024-1677
OESA-2024-1678
OESA-2024-1680
OESA-2024-1681
OESA-2024-1682
RHSA-2024:9315
RHSA-2024_9315
SUSE-SU-2024:2008-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2360-1
SUSE-SU-2024:2381-1
SUSE-SU-2024:2561-1
SUSE-SU-2024:2571-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6893-1
USN-6893-2
USN-6893-3
USN-6898-1
USN-6898-2
USN-6898-3
USN-6898-4
USN-6917-1
USN-6918-1
USN-6919-1
USN-6927-1
USN-6951-1
USN-6951-2
USN-6951-3
USN-6951-4
USN-6953-1
USN-6979-1
USN-7019-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu