{"api_version":"1","generated_at":"2026-07-23T14:00:23+00:00","cve":"CVE-2024-35983","urls":{"html":"https://cve.report/CVE-2024-35983","api":"https://cve.report/api/cve/CVE-2024-35983.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2024-35983","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2024-35983"},"summary":{"title":"bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS\n\nbits_per() rounds up to the next power of two when passed a power of\ntwo.  This causes crashes on some machines and configurations.","state":"PUBLISHED","assigner":"Linux","published_at":"2024-05-20 10:15:12","updated_at":"2026-05-12 12:16:45"},"problem_types":["NVD-CWE-noinfo"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}}],"references":[{"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html","name":"https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/93ba36238db6a74a82feb3dc476e25ea424ad630","name":"https://git.kernel.org/stable/c/93ba36238db6a74a82feb3dc476e25ea424ad630","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/9b7c5004d7c5ae062134052a85290869a015814c","name":"https://git.kernel.org/stable/c/9b7c5004d7c5ae062134052a85290869a015814c","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-265688.html","name":"https://cert-portal.siemens.com/productcert/html/ssa-265688.html","refsource":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ebfe41889b762f1933c6762f6624b9724a25bee0","name":"https://git.kernel.org/stable/c/ebfe41889b762f1933c6762f6624b9724a25bee0","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/15aa09d6d84629eb5296de30ac0aa19a33512f16","name":"https://git.kernel.org/stable/c/15aa09d6d84629eb5296de30ac0aa19a33512f16","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/66297b2ceda841f809637731d287bda3a93b49d8","name":"https://git.kernel.org/stable/c/66297b2ceda841f809637731d287bda3a93b49d8","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-613116.html","name":"https://cert-portal.siemens.com/productcert/html/ssa-613116.html","refsource":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/5af385f5f4cddf908f663974847a4083b2ff2c79","name":"https://git.kernel.org/stable/c/5af385f5f4cddf908f663974847a4083b2ff2c79","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/d34a516f2635090d36a306f84573e8de3d7374ce","name":"https://git.kernel.org/stable/c/d34a516f2635090d36a306f84573e8de3d7374ce","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-35983","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-35983","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected d6077e0d38b4953c863d0db4a5b3f41d21e0d546 d34a516f2635090d36a306f84573e8de3d7374ce git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 83a2275f9d3230c761014b1467888b1ef469be74 66297b2ceda841f809637731d287bda3a93b49d8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected d2a7a81088c6abe778b0a93a7eeb79487a943818 93ba36238db6a74a82feb3dc476e25ea424ad630 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 428ca0000f0abd5c99354c52a36becf2b815ca21 9b7c5004d7c5ae062134052a85290869a015814c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b46c822f8b555b9513df44047b0e72c06720df62 15aa09d6d84629eb5296de30ac0aa19a33512f16 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected cf778fff03be1ee88c49b72959650147573c3301 ebfe41889b762f1933c6762f6624b9724a25bee0 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f2d5dcb48f7ba9e3ff249d58fc1fa963d374e66a 5af385f5f4cddf908f663974847a4083b2ff2c79 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b2e1b090a590d41abe647eadb6bf2a5dc47b63ab git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.4.274 5.4.275 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.10.215 5.10.216 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.15.154 5.15.158 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.1.84 6.1.90 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.6.24 6.6.30 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.8.3 6.8.9 semver","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"RUGGEDCOM RST2428P","version":"affected V3.1 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family","version":"unaffected * custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SCALANCE XCM-/XRM-/XCH-/XRH-300 family","version":"affected V3.1 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SIMATIC S7-1500 TM MFP - GNU/Linux subsystem","version":"affected * custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2024","cve_id":"35983","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2024-35983","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2024-05-20T13:33:05.860363Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2024-06-04T17:34:16.061Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"},{"providerMetadata":{"dateUpdated":"2024-08-02T03:21:49.040Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/d34a516f2635090d36a306f84573e8de3d7374ce"},{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/66297b2ceda841f809637731d287bda3a93b49d8"},{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/93ba36238db6a74a82feb3dc476e25ea424ad630"},{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/9b7c5004d7c5ae062134052a85290869a015814c"},{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/15aa09d6d84629eb5296de30ac0aa19a33512f16"},{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/ebfe41889b762f1933c6762f6624b9724a25bee0"},{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/5af385f5f4cddf908f663974847a4083b2ff2c79"},{"tags":["x_transferred"],"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html"}],"title":"CVE Program Container"},{"affected":[{"defaultStatus":"unknown","product":"RUGGEDCOM RST2428P","vendor":"Siemens","versions":[{"lessThan":"V3.1","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family","vendor":"Siemens","versions":[{"lessThan":"*","status":"unaffected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SCALANCE XCM-/XRM-/XCH-/XRH-300 family","vendor":"Siemens","versions":[{"lessThan":"V3.1","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIMATIC S7-1500 TM MFP - GNU/Linux subsystem","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"0","versionType":"custom"}]}],"providerMetadata":{"dateUpdated":"2026-05-12T11:53:25.765Z","orgId":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","shortName":"siemens-SADP"},"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-265688.html"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-613116.html"}],"x_adpType":"supplier"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["kernel/bounds.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"d34a516f2635090d36a306f84573e8de3d7374ce","status":"affected","version":"d6077e0d38b4953c863d0db4a5b3f41d21e0d546","versionType":"git"},{"lessThan":"66297b2ceda841f809637731d287bda3a93b49d8","status":"affected","version":"83a2275f9d3230c761014b1467888b1ef469be74","versionType":"git"},{"lessThan":"93ba36238db6a74a82feb3dc476e25ea424ad630","status":"affected","version":"d2a7a81088c6abe778b0a93a7eeb79487a943818","versionType":"git"},{"lessThan":"9b7c5004d7c5ae062134052a85290869a015814c","status":"affected","version":"428ca0000f0abd5c99354c52a36becf2b815ca21","versionType":"git"},{"lessThan":"15aa09d6d84629eb5296de30ac0aa19a33512f16","status":"affected","version":"b46c822f8b555b9513df44047b0e72c06720df62","versionType":"git"},{"lessThan":"ebfe41889b762f1933c6762f6624b9724a25bee0","status":"affected","version":"cf778fff03be1ee88c49b72959650147573c3301","versionType":"git"},{"lessThan":"5af385f5f4cddf908f663974847a4083b2ff2c79","status":"affected","version":"f2d5dcb48f7ba9e3ff249d58fc1fa963d374e66a","versionType":"git"},{"status":"affected","version":"b2e1b090a590d41abe647eadb6bf2a5dc47b63ab","versionType":"git"}]},{"defaultStatus":"unaffected","product":"Linux","programFiles":["kernel/bounds.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"5.4.275","status":"affected","version":"5.4.274","versionType":"semver"},{"lessThan":"5.10.216","status":"affected","version":"5.10.215","versionType":"semver"},{"lessThan":"5.15.158","status":"affected","version":"5.15.154","versionType":"semver"},{"lessThan":"6.1.90","status":"affected","version":"6.1.84","versionType":"semver"},{"lessThan":"6.6.30","status":"affected","version":"6.6.24","versionType":"semver"},{"lessThan":"6.8.9","status":"affected","version":"6.8.3","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.4.275","versionStartIncluding":"5.4.274","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.216","versionStartIncluding":"5.10.215","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.158","versionStartIncluding":"5.15.154","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.90","versionStartIncluding":"6.1.84","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.30","versionStartIncluding":"6.6.24","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.8.9","versionStartIncluding":"6.8.3","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7.12","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS\n\nbits_per() rounds up to the next power of two when passed a power of\ntwo.  This causes crashes on some machines and configurations."}],"providerMetadata":{"dateUpdated":"2026-05-11T20:14:59.060Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/d34a516f2635090d36a306f84573e8de3d7374ce"},{"url":"https://git.kernel.org/stable/c/66297b2ceda841f809637731d287bda3a93b49d8"},{"url":"https://git.kernel.org/stable/c/93ba36238db6a74a82feb3dc476e25ea424ad630"},{"url":"https://git.kernel.org/stable/c/9b7c5004d7c5ae062134052a85290869a015814c"},{"url":"https://git.kernel.org/stable/c/15aa09d6d84629eb5296de30ac0aa19a33512f16"},{"url":"https://git.kernel.org/stable/c/ebfe41889b762f1933c6762f6624b9724a25bee0"},{"url":"https://git.kernel.org/stable/c/5af385f5f4cddf908f663974847a4083b2ff2c79"}],"title":"bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2024-35983","datePublished":"2024-05-20T09:47:51.079Z","dateReserved":"2024-05-17T13:50:33.145Z","dateUpdated":"2026-05-12T11:53:25.765Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2024-05-20 10:15:12","lastModifiedDate":"2026-05-12 12:16:45","problem_types":["NVD-CWE-noinfo"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.274","versionEndExcluding":"5.4.275","matchCriteriaId":"F5E54B56-9379-4599-9F82-9C47C3AD9481"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.215","versionEndExcluding":"5.10.216","matchCriteriaId":"B1A593F8-A32A-43C3-87CA-6EE8C4D8538A"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.154","versionEndExcluding":"5.15.158","matchCriteriaId":"5EAEFA87-47DC-4C73-A0C0-C1E4E436BC87"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.84","versionEndExcluding":"6.1.90","matchCriteriaId":"9466E6BB-FA8E-4F76-B8A6-FDE5100244D2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.24","versionEndExcluding":"6.6.30","matchCriteriaId":"C5ABE1B2-C67B-488F-81DD-A09351B51540"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7.12","versionEndExcluding":"6.8","matchCriteriaId":"D6A2C3EC-DA7B-4144-8BAF-2DBB7E8CE4C7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8.3","versionEndExcluding":"6.8.9","matchCriteriaId":"7EE73E8A-A1BD-47FF-99D8-99A4B5AC9B0B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2024","CveId":"35983","Ordinal":"1","Title":"bounds: Use the right number of bits for power-of-two CONFIG_NR_","CVE":"CVE-2024-35983","Year":"2024"},"notes":[{"CveYear":"2024","CveId":"35983","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nbounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS\n\nbits_per() rounds up to the next power of two when passed a power of\ntwo.  This causes crashes on some machines and configurations.","Type":"Description","Title":"bounds: Use the right number of bits for power-of-two CONFIG_NR_"}]}}}