CVE-2024-35951 is a medium-severity vulnerability in the Linux kernel's drm/panfrost driver, specifically within the panfrost_mmu_map_fault_addr() function. It involves an error handling flaw where an unbalanced get/put_pages() call could occur if page or scatter-gather table (SGT) allocations fail, leading to potential system instability. The vulnerability has a CVSS score of 5.5, indicating a local attack vector with low complexity, requiring low privileges, and resulting in high availability impact (denial of service). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.4, < 6.6.28CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.8.7CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.9CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:* | ||
6.9CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:* | ||
6.9CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.9:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025kernel: drm/panfrost: Fix the error path in panfrost_mmu_map_fault_addr()
May 20, 2024drm/panfrost: Fix the error path in panfrost_mmu_map_fault_addr()
May 14, 2024