CVE-2024-35878
Published: May 19, 2024
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: of: module: prevent NULL pointer dereference in vsnprintf() In of_modalias(), we can get passed the str and len parameters which would cause a kernel oops in vsnprintf() since it only allows passing a NULL ptr when the length is also 0. Also, we need to filter out the negative values of the len parameter as these will result in a really huge buffer since snprintf() takes size_t parameter while ours is ssize_t... Found by Linux Verification Center (linuxtesting.org) with the Svace static analysis tool.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected bd7a7ed774afd1a4174df34227626c95573be517 - < e4a449368a2ce6d57a775d0ead27fc07f5a86e5baffected bd7a7ed774afd1a4174df34227626c95573be517 - < 544561dc56f7e69a053c25e11e6170f48bb97898affected bd7a7ed774afd1a4174df34227626c95573be517 - < a1aa5390cc912934fee76ce80af5f940452fa987 |
Linux | Linux | affected 6.4unaffected 0 - < 6.4unaffected 6.6.26 - <= 6.6.*unaffected 6.8.5 - <= 6.8.*unaffected 6.9 - <= * |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now