Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-35982

17
FAUCET Score

CVE-2024-35982 is a vulnerability in the Linux kernel's batman-adv module that can lead to an infinite loop. This occurs when the MTU of an attached interface becomes too small to transmit the local translation table, causing the system to continuously attempt resizing without success. Rated as Medium severity (CVSS 5.5), it has a local attack vector with low complexity, requiring local privileges and resulting in high availability impact (denial of service). There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.13, < 4.19.313CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.275CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.216CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.156CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.87CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 72nd percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (15)

microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.22.1-2 on Azure Linux 3.0Fixed in: 6.6.35.1-5
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 5.15.158.1-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 6.6.35.1-5
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 6.6.35.1-5
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.153.1-2 on CBL Mariner 2.0Fixed in: 5.15.158.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.35.1-5 on Azure Linux 3.0Fixed in: -
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 5.15.158.1-1
microsoftpatch availablevia msrc
Product: 17671-17084Fixed in: -
microsoftpatch availablevia msrc
Product: 17325-16823Fixed in: 5.15.158.1-1
microsoftpatch availablevia msrc
Product: 19715-17086Fixed in: 5.15.158.1-1
microsoftpatch availablevia msrc
Product: 16839-17084Fixed in: 6.6.35.1-5
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.158.1-1 on CBL Mariner 2.0Fixed in: 5.15.158.1-1
nodejspatch availablevia llm_extracted
View patch
pjsippatch availablevia llm_extracted
View patch
oraclevendor investigatingvia oracle_oval
Product: cpe:/a:oracle:linux:6:10:UEKR4_ELS

Vendor Advisories (6)

nodejsllm-nodejs-302528ae26f0d946CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
pjsipllm-pjsip-7ba3ec379210ac70CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
microsoft2024-Sep/CVE-2024-35982

CVE-2024-35982

Sep 10, 2024
redhatCVE-2024-35982Moderate

kernel: batman-adv: Avoid infinite loop trying to resize local TT

May 20, 2024
microsoft2024-May/CVE-2024-35982Moderate

batman-adv: Avoid infinite loop trying to resize local TT

May 14, 2024
oracleoval:com.oracle.ovmsa:def:20240011IMPORTANT

OVMSA-2024-0011: Unbreakable Enterprise kernel security update (IMPORTANT)

References

cert-portal.siemens.com / productcert/html/ssa-265688.html
git.kernel.org / stable/c/04720ea2e6c64459a90ca28570ea78335eccd924
Patch
git.kernel.org / stable/c/3fe79b2c83461edbbf86ed8a6f3924820ff89259
Patch
git.kernel.org / stable/c/4ca2a5fb54ea2cc43edea614207fcede562d91c2
Patch
git.kernel.org / stable/c/70a8be9dc2fb65d67f8c1e0c88c587e08e2e575d
Patch
git.kernel.org / stable/c/87b6af1a7683e021710c08fc0551fc078346032f
Patch
git.kernel.org / stable/c/b1f532a3b1e6d2e5559c7ace49322922637a28aa
Patch
git.kernel.org / stable/c/b3ddf6904073990492454b1dd1c10a24be8c74c6
Patch
git.kernel.org / stable/c/ca54e2671548616ad34885f90d4f26f7adb088f0
Patch
lists.debian.org / debian-lts-announce/2024/06/msg00017.html
lists.debian.org / debian-lts-announce/2024/06/msg00020.html