Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-35892

17
FAUCET Score

CVE-2024-35892 is a vulnerability in the Linux kernel's networking scheduler, specifically within the qdisc_tree_reduce_backlog() function. It affects Linux kernel versions and stems from incorrect RCU (Read-Copy-Update) usage when the qdisc lock is held instead of the RTNL lock. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity. Successful exploitation could lead to a denial-of-service (DoS) condition due to a lockdep splat, causing system instability or crashes. There is no evidence of active exploitation, and no exploit code is publicly available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public attention.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.1.34, < 6.1.85CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.3.8, < 6.6.26CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.7, < 6.8.5CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
6.9CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:*
6.9CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
6.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0017 is in the 38th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-503.11.1.el9_5
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2024-35892Moderate

kernel: net/sched: fix lockdep splat in qdisc_tree_reduce_backlog()

May 19, 2024

References

git.kernel.org / stable/c/07696415526bee0607e495017369c7303a4792e1
Patch
git.kernel.org / stable/c/7eb322360b0266481e560d1807ee79e0cef5742b
Patch
git.kernel.org / stable/c/b7d1ce2cc7192e8a037faa3f5d3ba72c25976460
Patch
git.kernel.org / stable/c/c040b99461a5bfc14c2d0cbb1780fcc3a4706c7e
Patch