CVE-2024-35814 is a high-severity vulnerability in the Linux kernel's swiotlb component, affecting systems using bouncing via a restricted DMA SWIOTLB pool, particularly in virtual machines with vsock. The flaw stems from incorrect alignment handling during memory allocation, leading to double-allocation of memory slots. This can result in buffer corruption, system hangs, and potentially lead to a complete compromise of confidentiality, integrity, and availability. While the CVSS score is 8.8 (HIGH), there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.3, < 6.6.24CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.7.12CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.8, < 6.8.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.