PT-2024-8338 · Linux+5 · Linux Kernel+5
David Sterba
·
Published
2024-03-04
·
Updated
2025-02-03
·
CVE-2024-35935
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to the btrfs send component in the Linux kernel, specifically with error handling in the
iterate inode ref() function. This can potentially lead to a denial of service. The problem arises when building the path buffer fails, and the code has been updated to handle this situation properly, preventing potential kernel address leaks.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu