Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-35849

19
FAUCET Score

CVE-2024-35849 is an information leak vulnerability in the Linux kernel's Btrfs filesystem, specifically affecting the btrfs_ioctl_logical_to_ino() function. This flaw allows an attacker to read uninitialized kernel memory due to the use of kvmalloc() instead of kvzalloc() for memory allocation, which does not zero-fill the memory. It impacts various Linux distributions, including Debian. Rated as High severity with a CVSS score of 7.1, this vulnerability has a local attack vector and low attack complexity. A successful exploit could lead to a high impact on confidentiality, allowing an authenticated local attacker to potentially gain sensitive information from kernel memory. There is no impact on integrity or availability. Currently, there is no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.19.313CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.275CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.216CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.158CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.90CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 52nd percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

codesyspatch availablevia llm_extracted
View patch
esphomepatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: azl3 hyperv-daemons 6.6.29.1-1 on Azure Linux 3.0Fixed in: 6.6.35.1-1
microsoftpatch availablevia msrc
Product: 17748-17084Fixed in: 6.6.35.1-1
microsoftpatch availablevia msrc
Product: azl3 hyperv-daemons 6.6.35.1-1 on Azure Linux 3.0Fixed in: 6.6.35.1-1
microsoftpatch availablevia msrc
Product: 16989-17084Fixed in: 6.6.35.1-1
nodejspatch availablevia llm_extracted
View patch
pjsippatch availablevia llm_extracted
View patch

Vendor Advisories (6)

codesysllm-codesys-fe85e88fbae25bb9CRITICAL

HP ThinPro 8.1 SP7 Security Updates

Jun 3, 2025
esphomellm-esphome-ed450ce9fd6a7380CRITICAL

HP ThinPro 8.1 SP7 Security Updates

Jun 3, 2025
nodejsllm-nodejs-302528ae26f0d946CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
pjsipllm-pjsip-7ba3ec379210ac70CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
redhatCVE-2024-35849Low

kernel: btrfs: fix information leak in btrfs_ioctl_logical_to_ino()

May 17, 2024
microsoft2024-May/CVE-2024-35849Important

btrfs: fix information leak in btrfs_ioctl_logical_to_ino()

May 14, 2024

References

cert-portal.siemens.com / productcert/html/ssa-265688.html
git.kernel.org / stable/c/2f7ef5bb4a2f3e481ef05fab946edb97c84f67cf
Patch
git.kernel.org / stable/c/30189e54ba80e3209d34cfeea87b848f6ae025e6
Patch
git.kernel.org / stable/c/3a63cee1a5e14a3e52c19142c61dd5fcb524f6dc
Patch
git.kernel.org / stable/c/689efe22e9b5b7d9d523119a9a5c3c17107a0772
Patch
git.kernel.org / stable/c/73db209dcd4ae026021234d40cfcb2fb5b564b86
Patch
git.kernel.org / stable/c/8bdbcfaf3eac42f98e5486b3d7e130fa287811f6
Patch
git.kernel.org / stable/c/e58047553a4e859dafc8d1d901e1de77c9dd922d
Patch
git.kernel.org / stable/c/fddc19631c51d9c17d43e9f822a7bc403af88d54
Patch
lists.debian.org / debian-lts-announce/2024/06/msg00017.html
Mailing List
lists.debian.org / debian-lts-announce/2024/06/msg00020.html
Mailing List