CVE-2024-35982 is a vulnerability in the Linux kernel's batman-adv module that can lead to an infinite loop. This occurs when the MTU of an attached interface becomes too small to transmit the local translation table, causing the system to continuously attempt resizing without success. Rated as Medium severity (CVSS 5.5), it has a local attack vector with low complexity, requiring local privileges and resulting in high availability impact (denial of service). There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.13, < 4.19.313CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.20, < 5.4.275CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.216CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.156CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.87CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP4 Security Updates
Oct 29, 2024HP ThinPro 8.1 SP4 Security Updates
Oct 29, 2024CVE-2024-35982
Sep 10, 2024kernel: batman-adv: Avoid infinite loop trying to resize local TT
May 20, 2024batman-adv: Avoid infinite loop trying to resize local TT
May 14, 2024OVMSA-2024-0011: Unbreakable Enterprise kernel security update (IMPORTANT)