CVE-2024-35849 is an information leak vulnerability in the Linux kernel's Btrfs filesystem, specifically affecting the btrfs_ioctl_logical_to_ino() function. This flaw allows an attacker to read uninitialized kernel memory due to the use of kvmalloc() instead of kvzalloc() for memory allocation, which does not zero-fill the memory. It impacts various Linux distributions, including Debian. Rated as High severity with a CVSS score of 7.1, this vulnerability has a local attack vector and low attack complexity. A successful exploit could lead to a high impact on confidentiality, allowing an authenticated local attacker to potentially gain sensitive information from kernel memory. There is no impact on integrity or availability. Currently, there is no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.19.313CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.20, < 5.4.275CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.216CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.158CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.90CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025HP ThinPro 8.1 SP4 Security Updates
Oct 29, 2024HP ThinPro 8.1 SP4 Security Updates
Oct 29, 2024kernel: btrfs: fix information leak in btrfs_ioctl_logical_to_ino()
May 17, 2024btrfs: fix information leak in btrfs_ioctl_logical_to_ino()
May 14, 2024