bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS
Summary
| CVE | CVE-2024-35983 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-05-20 10:15:12 UTC |
| Updated | 2026-05-12 12:16:45 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS bits_per() rounds up to the next power of two when passed a power of two. This causes crashes on some machines and configurations. |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Problem Types: NVD-CWE-noinfo
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected d6077e0d38b4953c863d0db4a5b3f41d21e0d546 d34a516f2635090d36a306f84573e8de3d7374ce git | Not specified |
| CNA | Linux | Linux | affected 83a2275f9d3230c761014b1467888b1ef469be74 66297b2ceda841f809637731d287bda3a93b49d8 git | Not specified |
| CNA | Linux | Linux | affected d2a7a81088c6abe778b0a93a7eeb79487a943818 93ba36238db6a74a82feb3dc476e25ea424ad630 git | Not specified |
| CNA | Linux | Linux | affected 428ca0000f0abd5c99354c52a36becf2b815ca21 9b7c5004d7c5ae062134052a85290869a015814c git | Not specified |
| CNA | Linux | Linux | affected b46c822f8b555b9513df44047b0e72c06720df62 15aa09d6d84629eb5296de30ac0aa19a33512f16 git | Not specified |
| CNA | Linux | Linux | affected cf778fff03be1ee88c49b72959650147573c3301 ebfe41889b762f1933c6762f6624b9724a25bee0 git | Not specified |
| CNA | Linux | Linux | affected f2d5dcb48f7ba9e3ff249d58fc1fa963d374e66a 5af385f5f4cddf908f663974847a4083b2ff2c79 git | Not specified |
| CNA | Linux | Linux | affected b2e1b090a590d41abe647eadb6bf2a5dc47b63ab git | Not specified |
| CNA | Linux | Linux | affected 5.4.274 5.4.275 semver | Not specified |
| CNA | Linux | Linux | affected 5.10.215 5.10.216 semver | Not specified |
| CNA | Linux | Linux | affected 5.15.154 5.15.158 semver | Not specified |
| CNA | Linux | Linux | affected 6.1.84 6.1.90 semver | Not specified |
| CNA | Linux | Linux | affected 6.6.24 6.6.30 semver | Not specified |
| CNA | Linux | Linux | affected 6.8.3 6.8.9 semver | Not specified |
| ADP | Siemens | RUGGEDCOM RST2428P | affected V3.1 custom | Not specified |
| ADP | Siemens | SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 Family | unaffected * custom | Not specified |
| ADP | Siemens | SCALANCE XCM-/XRM-/XCH-/XRH-300 Family | affected V3.1 custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 TM MFP - GNU/Linux Subsystem | affected * custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| lists.debian.org/debian-lts-announce/2024/06/msg00017.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | Patch |
| git.kernel.org/stable/c/93ba36238db6a74a82feb3dc476e25ea424ad630 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/9b7c5004d7c5ae062134052a85290869a015814c | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| cert-portal.siemens.com/productcert/html/ssa-265688.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| git.kernel.org/stable/c/ebfe41889b762f1933c6762f6624b9724a25bee0 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/15aa09d6d84629eb5296de30ac0aa19a33512f16 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/66297b2ceda841f809637731d287bda3a93b49d8 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| cert-portal.siemens.com/productcert/html/ssa-613116.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| git.kernel.org/stable/c/5af385f5f4cddf908f663974847a4083b2ff2c79 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/d34a516f2635090d36a306f84573e8de3d7374ce | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.