PT-2024-8488 · Linux+9 · Linux Kernel+9

Syzbot

·

Published

2024-03-29

·

Updated

2025-09-29

·

CVE-2024-35888

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.9.0-rc1-syzkaller-00021-g962490525cff
Description The issue is related to the erspan component in the Linux kernel, where the ip6erspan rcv() function does not ensure that erspan base hdr is present in the skb linear part before accessing the @ver field. This can lead to an uninitialized value being used, potentially causing a denial-of-service. The vulnerability was reported by syzbot and is fixed by adding missing pskb may pull() calls.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix, which is at least 6.9.0-rc1-syzkaller-00021-g962490525cff or later. If updating is not possible, consider disabling the erspan component as a temporary workaround to minimize the risk of exploitation.

Exploit

Fix

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:4211
ALSA-2024:4352
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
BDU:2024-10048
CESA-2024_4211
CESA-2024_4352
CVE-2024-35888
DLA-3840-1
DLA-3842-1
INFSA-2024_4211
INFSA-2024_4352
INFSA-2024_9315
OESA-2024-1705
OESA-2024-1706
OESA-2024-1707
OPENSUSE-SU-2024_4314-1
OPENSUSE-SU-2024_4315-1
OPENSUSE-SU-2024_4316-1
OPENSUSE-SU-2024_4376-1
RHSA-2024:4211
RHSA-2024:4352
RHSA-2024:9315
RHSA-2024_4211
RHSA-2024_4352
RHSA-2024_9315
RHSA-2025:3510
RLSA-2024:4211
RLSA-2024:4352
RXSA-2024:4211
SUSE-SU-2024:4314-1
SUSE-SU-2024:4315-1
SUSE-SU-2024:4316-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4376-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-6893-1
USN-6893-2
USN-6893-3
USN-6896-1
USN-6896-2
USN-6896-3
USN-6896-4
USN-6896-5
USN-6898-1
USN-6898-2
USN-6898-3
USN-6898-4
USN-6917-1
USN-6918-1
USN-6919-1
USN-6927-1
USN-7019-1

Affected Products

Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu