CVE-2024-35826: block: Fix page refcounts for unaligned buffers in __bio_release_pages()
Published May 17, 2024
·Updated
block: Fix page refcounts for unaligned buffers in bioreleasepages()
Affected Software
10 affected componentsFixes available
debian/linux<=5.10.223-1, <=5.10.234-1
6.1.129-16.1.135-16.12.25-16.12.27-1
Linux Linux kernel>=4.19.307<4.20
Linux Linux kernel>=5.4.269<5.5
Linux Linux kernel>=5.10.210<5.11
Linux Linux kernel>=5.15.148<5.16
Linux Linux kernel>=6.1.75<6.1.84
Linux Linux kernel>=6.6.14<6.6.24
Linux Linux kernel>=6.7.2<6.7.12
Linux Linux kernel>=6.8<6.8.3
Microsoft cbl2 kernel 5.15.186.1-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
Event History
May 17, 2024
CVE Published
via MITRE·01:27 PM
Data Sourced
via MITRE·01:27 PM
Description
Data Sourced
via NVD·02:15 PM
Description
Data Sourced
via NVD·02:15 PM
RemedySeverityAffected Software
Jun 8, 2024
Data Sourced
via Launchpad·01:18 AM
Description
Apr 29, 2025
Data Sourced
via Ubuntu·06:21 AM
RemedyDescriptionSeverityAffected Software
Sep 28, 2025
Data Sourced
via Microsoft·01:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:01 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-35826?
CVE-2024-35826 is classified as a medium severity vulnerability due to the potential for improper resource management.
2
How do I fix CVE-2024-35826?
To fix CVE-2024-35826, upgrade the Linux kernel to versions 6.1.123-1, 6.1.119-1, 6.12.11-1, or 6.12.12-1.
3
Which Linux kernel versions are affected by CVE-2024-35826?
CVE-2024-35826 affects Linux kernel versions up to and including 5.10.226-1.
4
What type of issue is CVE-2024-35826 related to?
CVE-2024-35826 is related to incorrect reference counting of pages for unaligned buffers in the Linux kernel.
5
Is CVE-2024-35826 a significant security risk?
While CVE-2024-35826 is not classified as critical, it can lead to resource mismanagement issues that may affect system stability.