CVE-2024-35837

In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: clear BM pool before initialization Register value persist after booting the kernel using kexec which results in kernel panic. Thus clear the BM pool registers before initialisation to fix the issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

17 Dec 2025, 19:22

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/83f99138bf3b396f761600ab488054396fb5768f - () https://git.kernel.org/stable/c/83f99138bf3b396f761600ab488054396fb5768f - Patch
References () https://git.kernel.org/stable/c/938729484cfa535e9987ed0f86f29a2ae3a8188b - () https://git.kernel.org/stable/c/938729484cfa535e9987ed0f86f29a2ae3a8188b - Patch
References () https://git.kernel.org/stable/c/9f538b415db862e74b8c5d3abbccfc1b2b6caa38 - () https://git.kernel.org/stable/c/9f538b415db862e74b8c5d3abbccfc1b2b6caa38 - Patch
References () https://git.kernel.org/stable/c/af47faa6d3328406038b731794e7cf508c71affa - () https://git.kernel.org/stable/c/af47faa6d3328406038b731794e7cf508c71affa - Patch
References () https://git.kernel.org/stable/c/cec65f09c47d8c2d67f2bcad6cf05c490628d1ec - () https://git.kernel.org/stable/c/cec65f09c47d8c2d67f2bcad6cf05c490628d1ec - Patch
References () https://git.kernel.org/stable/c/dc77f6ab5c3759df60ff87ed24f4d45df0f3b4c4 - () https://git.kernel.org/stable/c/dc77f6ab5c3759df60ff87ed24f4d45df0f3b4c4 - Patch
References () https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html - () https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html - Third Party Advisory
First Time Linux
Debian
Debian debian Linux
Linux linux Kernel
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

21 Nov 2024, 09:21

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html -
References () https://git.kernel.org/stable/c/83f99138bf3b396f761600ab488054396fb5768f - () https://git.kernel.org/stable/c/83f99138bf3b396f761600ab488054396fb5768f -
References () https://git.kernel.org/stable/c/938729484cfa535e9987ed0f86f29a2ae3a8188b - () https://git.kernel.org/stable/c/938729484cfa535e9987ed0f86f29a2ae3a8188b -
References () https://git.kernel.org/stable/c/9f538b415db862e74b8c5d3abbccfc1b2b6caa38 - () https://git.kernel.org/stable/c/9f538b415db862e74b8c5d3abbccfc1b2b6caa38 -
References () https://git.kernel.org/stable/c/af47faa6d3328406038b731794e7cf508c71affa - () https://git.kernel.org/stable/c/af47faa6d3328406038b731794e7cf508c71affa -
References () https://git.kernel.org/stable/c/cec65f09c47d8c2d67f2bcad6cf05c490628d1ec - () https://git.kernel.org/stable/c/cec65f09c47d8c2d67f2bcad6cf05c490628d1ec -
References () https://git.kernel.org/stable/c/dc77f6ab5c3759df60ff87ed24f4d45df0f3b4c4 - () https://git.kernel.org/stable/c/dc77f6ab5c3759df60ff87ed24f4d45df0f3b4c4 -

05 Nov 2024, 10:16

Type Values Removed Values Added
References
  • {'url': 'https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html', 'source': '416baaa9-dc9f-4396-8d5f-8c081fb06d67'}

25 Jun 2024, 22:15

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se resolvió la siguiente vulnerabilidad: net: mvpp2: borre el grupo de BM antes de la inicialización. El valor del registro persiste después de iniciar el kernel usando kexec, lo que genera pánico en el kernel. Por lo tanto, borre los registros del grupo BM antes de la inicialización para solucionar el problema.
References
  • () https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html -

17 May 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-17 14:15

Updated : 2025-12-17 19:22


NVD link : CVE-2024-35837

Mitre link : CVE-2024-35837

CVE.ORG link : CVE-2024-35837


JSON object : View

Products Affected

debian

  • debian_linux

linux

  • linux_kernel