First published: Fri May 17 2024(Updated: )
In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: clear BM pool before initialization Register value persist after booting the kernel using kexec which results in kernel panic. Thus clear the BM pool registers before initialisation to fix the issue.
Credit: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Software | Affected Version | How to fix |
---|---|---|
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.119-1 6.12.11-1 6.12.12-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35837 is considered a high severity vulnerability due to its potential to cause kernel panic.
To fix CVE-2024-35837, update your Linux kernel to one of the patched versions, such as 5.10.223-1 or 6.12.12-1.
CVE-2024-35837 affects specific versions of the Linux kernel found in Debian, including version 5.10.223-1 and 6.12.12-1.
CVE-2024-35837 is caused by the persistence of register values after booting using kexec, resulting in kernel panic.
There is no official workaround for CVE-2024-35837; applying the software update is the only recommended solution.