CVE-2024-35800
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
17/05/2024
Last modified:
19/09/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
efi: fix panic in kdump kernel<br />
<br />
Check if get_next_variable() is actually valid pointer before<br />
calling it. In kdump kernel this method is set to NULL that causes<br />
panic during the kexec-ed kernel boot.<br />
<br />
Tested with QEMU and OVMF firmware.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.1.81 (including) | 6.1.84 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.3 (including) | 6.6.24 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.7.12 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.8 (including) | 6.8.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/090d2b4515ade379cd592fbc8931344945978210
- https://git.kernel.org/stable/c/62b71cd73d41ddac6b1760402bbe8c4932e23531
- https://git.kernel.org/stable/c/7784135f134c13af17d9ffb39a57db8500bc60ff
- https://git.kernel.org/stable/c/9114ba9987506bcfbb454f6e68558d68cb1abbde
- https://git.kernel.org/stable/c/b9d103aca85f082a343b222493f3cab1219aaaf4
- https://git.kernel.org/stable/c/090d2b4515ade379cd592fbc8931344945978210
- https://git.kernel.org/stable/c/62b71cd73d41ddac6b1760402bbe8c4932e23531
- https://git.kernel.org/stable/c/7784135f134c13af17d9ffb39a57db8500bc60ff
- https://git.kernel.org/stable/c/9114ba9987506bcfbb454f6e68558d68cb1abbde
- https://git.kernel.org/stable/c/b9d103aca85f082a343b222493f3cab1219aaaf4



