CVE-2024-35995 is a vulnerability in the Linux kernel's ACPI CPPC module, specifically affecting how it handles system memory accesses. The issue arises because the kernel incorrectly uses bit_width instead of access_width, leading to potential data corruption or system instability on certain platforms, such as Cobalt 100. This flaw can cause a kernel panic, as demonstrated by the provided stack trace. The vulnerability has a CVSS score of 5.5 (MEDIUM), indicating a local attack vector with low attack complexity and requiring low privileges. Its primary impact is high availability loss (A:H), meaning it can cause system crashes or denial of service, but it does not directly impact confidentiality or integrity. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion and media coverage, suggesting a low level of public awareness or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.1.90CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.30CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.8.9CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.