CVE-2024-35997: HID: i2c-hid: remove I2C_HID_READ_PENDING flag to prevent lock-up
Published May 20, 2024
·Updated
HID: i2c-hid: remove I2CHIDREADPENDING flag to prevent lock-up
Affected Software
12 affected componentsFixes available
Linux Linux kernel>=3.8<4.19.313
Linux Linux kernel>=4.20<5.4.275
Linux Linux kernel>=5.5<5.10.216
Linux Linux kernel>=5.11<5.15.158
Linux Linux kernel>=5.16<6.1.90
Linux Linux kernel>=6.2<6.6.30
Linux Linux kernel>=6.7<6.8.9
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.27-1
Microsoft azl3 kernel 6.6.35.1-4
Microsoft cbl2 kernel 5.15.158.1-1
Microsoft cbl2 kernel 5.15.153.1-2
Microsoft azl3 kernel 6.6.29.1-5
Remediation
Event History
May 20, 2024
CVE Published
via MITRE·09:48 AM
Data Sourced
via MITRE·09:48 AM
Description
Data Sourced
via NVD·10:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
May 24, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Jul 12, 2024
Data Sourced
via Launchpad·02:47 PM
Description
May 5, 2025
Data Sourced
via Ubuntu·12:27 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35997?
CVE-2024-35997 has not been assigned a CVSS score but is considered significant due to its potential impact on I2C operations.
2
How do I fix CVE-2024-35997?
To fix CVE-2024-35997, upgrade to Linux kernel versions 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.9-1, or 6.12.10-1.
3
What impact does CVE-2024-35997 have on the Linux kernel?
CVE-2024-35997 can lead to lock-ups in I2C operations by improperly handling the I2C_HID_READ_PENDING flag.
4
Which Linux kernel versions are affected by CVE-2024-35997?
CVE-2024-35997 affects various versions of the Linux kernel from 3.8 up to 6.8.9.
5
Is there a workaround for CVE-2024-35997?
There is no documented workaround for CVE-2024-35997; updating the kernel is recommended.