PT-2024-3848 · Linux+9 · Linux Kernel+9

Published

2024-04-24

·

Updated

2025-09-29

·

CVE-2024-35854

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.37
Description The issue is related to a possible use-after-free during rehash in the mlxsw spectrum acl tcam module. The rehash delayed work migrates filters from one region to another according to the number of available credits. However, the assumption that a non-negative number of credits indicates migration being complete is incorrect, as it can also result from a failed migration. This can lead to the destruction of a region that still has filters referencing it, resulting in a use-after-free. The fix is to not destroy the region if migration failed.
Recommendations To resolve the issue, update the Linux kernel to version 6.6.37 or later. As a temporary workaround, consider disabling the mlxsw sp acl tcam vregion rehash work function until a patch is available. Restrict access to the vulnerable module mlxsw sp acl tcam to minimize the risk of exploitation. Avoid using the mlxsw sp acl ctcam region entry remove function in the affected API endpoint until the issue is resolved.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:4211
ALSA-2024:4352
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
AZL-42100
BDU:2024-04228
CESA-2024_4211
CESA-2024_4352
CVE-2024-35854
DLA-3842-1
INFSA-2024_4211
INFSA-2024_4352
INFSA-2024_9315
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-1706
OESA-2024-1707
OPENSUSE-SU-2024_2947-1
RHSA-2024:4211
RHSA-2024:4352
RHSA-2024:9315
RHSA-2024_4211
RHSA-2024_4352
RHSA-2024_9315
RHSA-2025:3215
RLSA-2024:4211
RLSA-2024:4352
RXSA-2024:4211
SUSE-SU-2024:2008-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2135-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2802-1
SUSE-SU-2024:2894-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2947-1
SUSE-SU-2024:2973-1
SUSE-SU-2024:3194-1
SUSE-SU-2024:3383-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6896-1
USN-6896-2
USN-6896-3
USN-6896-4
USN-6896-5
USN-6898-1
USN-6898-2
USN-6898-3
USN-6898-4
USN-6917-1
USN-6919-1
USN-6927-1
USN-6949-1
USN-6949-2
USN-6952-1
USN-6952-2
USN-6955-1
USN-7019-1

Affected Products

Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu