CVE Database
/

CVE-2024-35878

Back to search

CVE-2024-35878

Published: May 19, 2024

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: of: module: prevent NULL pointer dereference in vsnprintf() In of_modalias(), we can get passed the str and len parameters which would cause a kernel oops in vsnprintf() since it only allows passing a NULL ptr when the length is also 0. Also, we need to filter out the negative values of the len parameter as these will result in a really huge buffer since snprintf() takes size_t parameter while ours is ssize_t... Found by Linux Verification Center (linuxtesting.org) with the Svace static analysis tool.

VendorProductVersions

Linux

Linux

affected
bd7a7ed774afd1a4174df34227626c95573be517 - < e4a449368a2ce6d57a775d0ead27fc07f5a86e5b
affected
bd7a7ed774afd1a4174df34227626c95573be517 - < 544561dc56f7e69a053c25e11e6170f48bb97898
affected
bd7a7ed774afd1a4174df34227626c95573be517 - < a1aa5390cc912934fee76ce80af5f940452fa987

Linux

Linux

affected
6.4
unaffected
0 - < 6.4
unaffected
6.6.26 - <= 6.6.*
unaffected
6.8.5 - <= 6.8.*
unaffected
6.9 - <= *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now