CVE-2024-35813: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: mmc: core: Avoid negative index with array access Commit 4d0c8d0aef63 ("mmc: core: Use mrq.sbc in close-ended ffu") assigns prev_idata = idatas[i - 1], but doesn't check that the iterator i is greater than zero. Let's fix this by adding a check.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Linux Linux Kernel: from 5.4.269, before 5.4.274 (fixed in 5.4.274); from 5.10.210, before 5.10.215 (fixed in 5.10.215); from 5.15.149, before 5.15.154 (fixed in 5.15.154); from 6.1.76, before 6.1.84 (fixed in 6.1.84); from 6.6.15, before 6.6.24 (fixed in 6.6.24); from 6.7.3, before 6.7.12 (fixed in 6.7.12); …

Published 2024-05-17. Last modified 2026-08-04.