Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-35835

18
FAUCET Score

CVE-2024-35835 is a double-free vulnerability in the Linux kernel's net/mlx5e driver, specifically within the arfs_create_groups function, affecting Debian and other Linux kernel versions. The flaw occurs when memory allocation fails, leading to ft->g being freed twice. This vulnerability has a CVSS score of 5.3 (Medium), indicating a network-based attack with low complexity, but only a low impact on confidentiality and no impact on integrity or availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.7, < 4.19.307CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.269CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.210CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.149CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.76CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.86%
Probability of exploitation in next 30 days
EPSS Percentile
54.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0086 is in the 34th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-553.8.1.rt7.349.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.8.1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-503.11.1.el9_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: kernel-0:5.14.0-427.60.1.el9_4
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2024-35835Moderate

kernel: net/mlx5e: fix a double-free in arfs_create_groups

May 17, 2024

References

git.kernel.org / stable/c/2501afe6c4c9829d03abe9a368b83d9ea1b611b7
Patch
git.kernel.org / stable/c/3c6d5189246f590e4e1f167991558bdb72a4738b
Patch
git.kernel.org / stable/c/42876db001bbea7558e8676d1019f08f9390addb
Patch
git.kernel.org / stable/c/66cc521a739ccd5da057a1cb3d6346c6d0e7619b
Patch
git.kernel.org / stable/c/b21db3f1ab7967a81d6bbd328d28fe5a4c07a8a7
Patch
git.kernel.org / stable/c/c57ca114eb00e03274dd38108d07a3750fa3c056
Patch
git.kernel.org / stable/c/cf116d9c3c2aebd653c2dfab5b10c278e9ec3ee5
Patch
git.kernel.org / stable/c/e3d3ed8c152971dbe64c92c9ecb98fdb52abb629
Patch
lists.debian.org / debian-lts-announce/2024/06/msg00017.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2024/06/msg00020.html
Mailing ListThird Party Advisory