PT-2024-8338 · Linux+5 · Linux Kernel+5

David Sterba

·

Published

2024-03-04

·

Updated

2025-02-03

·

CVE-2024-35935

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the btrfs send component in the Linux kernel, specifically with error handling in the iterate inode ref() function. This can potentially lead to a denial of service. The problem arises when building the path buffer fails, and the code has been updated to handle this situation properly, preventing potential kernel address leaks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09894
CVE-2024-35935
DLA-3840-1
DLA-3842-1
OESA-2024-1736
OESA-2024-1737
OESA-2024-1738
SUSE-SU-2024:1979-1
SUSE-SU-2024:1983-1
SUSE-SU-2024:2008-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2135-1
SUSE-SU-2024:2184-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6893-1
USN-6893-2
USN-6893-3
USN-6896-1
USN-6896-2
USN-6896-3
USN-6896-4
USN-6896-5
USN-6898-1
USN-6898-2
USN-6898-3
USN-6898-4
USN-6917-1
USN-6918-1
USN-6919-1
USN-6927-1
USN-7019-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu