Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-35995

17
FAUCET Score

CVE-2024-35995 is a vulnerability in the Linux kernel's ACPI CPPC module, specifically affecting how it handles system memory accesses. The issue arises because the kernel incorrectly uses bit_width instead of access_width, leading to potential data corruption or system instability on certain platforms, such as Cobalt 100. This flaw can cause a kernel panic, as demonstrated by the provided stack trace. The vulnerability has a CVSS score of 5.5 (MEDIUM), indicating a local attack vector with low attack complexity and requiring low privileges. Its primary impact is high availability loss (A:H), meaning it can cause system crashes or denial of service, but it does not directly impact confidentiality or integrity. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion and media coverage, suggesting a low level of public awareness or concern.

Impacted Technologies

VendorProductVersion(s)CPE
< 6.1.90CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.30CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.7, < 6.8.9CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
11.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0021 is in the 52nd percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-503.11.1.el9_5
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt

Vendor Advisories (2)

redhatCVE-2024-35995Low

kernel: ACPI: CPPC: Use access_width over bit_width for system memory accesses

May 20, 2024
microsoft2024-May/CVE-2024-35995Moderate

ACPI: CPPC: Use access_width over bit_width for system memory accesses

May 14, 2024

References

git.kernel.org / stable/c/01fc53be672acae37e611c80cc0b4f3939584de3
Patch
git.kernel.org / stable/c/1b890ae474d19800a6be1696df7fb4d9a41676e4
Patch
git.kernel.org / stable/c/2f4a4d63a193be6fd530d180bb13c3592052904c
Patch
git.kernel.org / stable/c/6cb6b12b78dcd8867a3fdbb1b6d0ed1df2b208d1
Patch
git.kernel.org / stable/c/4949affd5288b867cdf115f5b08d6166b2027f87
Patch
git.kernel.org / stable/c/6dfd79ed04c578f1d9a9a41ba5b2015cf9f03fc3
Patch
git.kernel.org / stable/c/b54c4632946ae42f2b39ed38abd909bbf78cbcc2
Patch