AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-35878

MEDIUM · CVSS 5.3 EPSS 0.79%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-05-19 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.3. It affects Linux.

CVE
CVE-2024-35878
Severity
MEDIUM
CVSS
5.3
EPSS
0.79%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: of: module: prevent NULL pointer dereference in vsnprintf() In of_modalias(), we can get passed the str and len parameters which would cause a kernel oops in vsnprintf() since it only allows passing a NULL ptr when the length is also 0. Also, we need to filter out the negative values of the len parameter as these will result in a really huge buffer since snprintf() takes size_t parameter while ours is ssize_t... Found by Linux Verification Center (linuxtesting.org) with the Svace static analysis tool.

Related CVEs

Other vulnerabilities affecting the same vendor(s)