Get real-time updates on Telegram
CVE-2024-35937: debian linux 11.0; +2 more affected products
CVE-2024-35937. CVSS 3.1 base score 7.1 (HIGH, NVD). EPSS 0.00344 (percentile 0.25853), scored 2026-10-08.
Affected technology
debian linux · 11.0
debian
linux kernel · from 6.3 (inclusive), before 6.6.27 (exclusive)
linux
linux kernel · from 6.7 (inclusive), before 6.8.6 (exclusive)
linux
Linux · 966d5c2c22edcc0ab3d519af39f91a29329c979a to before 9eb3bc0973d084423a6df21cf2c74692ff05647e, 6e4c0d0460bd32ca9244dff3ba2d2da27235de11 to before 5d7a8585fbb31e88fb2a0f581b70667d3300d1e9, 6e4c0d0460bd32ca9244dff3ba2d2da27235de11 to before 16da1e1dac23be45ef6e23c41b1508c400e6c544, 6e4c0d0460bd32ca9244dff3ba2d2da27235de11 to before 9ad7974856926129f190ffbe3beea78460b3b7cc
Linux
Linux · 6.3
Linux
Component: Not specified by the source
File: net/wireless/util.c
Attack conditions (Source advisory, CVSS 3.1): Adjacent network · No privileges required · No user interaction required
Attack conditions (NVD, CVSS 3.1): Local · Low privileges required · No user interaction required
What an attacker can do
Source advisory’s CVSS 3.1 assessment (base score 8.1/10) rates confidentiality and availability impact as high; integrity impact as none. NVD’s CVSS 3.1 assessment (base score 7.1/10) rates confidentiality and availability impact as high; integrity impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
- CWE
- CWE-125
- CCR priority
- 28.5 /100 (P4)
- CVSS 3.1
- 7.1 /10 · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H · NVD
- EPSS
- 0.00344 · percentile 0.25853 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-08 18:34:48.508309+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2024-35937.html