CVE-2024-35800
MEDIUMLinux Kernel - NULL Pointer Dereference in EFI Variable Handling
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: efi: fix panic in kdump kernel Check if get_next_variable() is actually valid pointer before calling it. In kdump kernel this method is set to NULL that causes panic during the kexec-ed kernel boot. Tested with QEMU and OVMF firmware.
References (5)
Core 5
Core References
Scores
CVSS v3
5.5
EPSS
0.0022
EPSS Percentile
13.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-476
Status
published
Products (18)
linux/Kernel
< 6.1.84linux
linux/Kernel
6.2.0 - 6.6.24linux
linux/Kernel
6.3.0 - 6.7.12linux
linux/Kernel
6.7.0 - 6.8.3linux
Linux/Linux
< 6.3
Linux/Linux
6.1.81 - 6.1.84
Linux/Linux
6.1.84 - 6.1.*
Linux/Linux
6.3
Linux/Linux
6.6.24 - 6.6.*
Linux/Linux
6.7.12 - 6.7.*
... and 8 more
Published
May 17, 2024
Tracked Since
Feb 18, 2026