CVE-2024-36028 is a vulnerability in the Linux kernel, specifically within the HugeTLB memory management subsystem. It arises from an issue where the _deferred_list and _hugetlb_subpool fields of a folio are improperly unioned, leading to a DEBUG_LOCKS_WARN_ON(1) error during memory failure tests. This flaw affects Linux kernel versions and can result in a kernel panic, causing system unavailability. The vulnerability has a CVSS score of 4.7 MEDIUM, indicating a moderate severity. It requires local access and high attack complexity (AV:L/AC:H), meaning an attacker would need specific conditions and privileges to trigger it. The primary impact is a denial of service (A:H) due to the kernel panic, with no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for a significant portion of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.1.47, < 6.1.91CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.4.11, < 6.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.5.1, < 6.6.31CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.8.9CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.5:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.