CVE-2024-35847: Debian Linux

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Prevent double free on error The error handling path in its_vpe_irq_domain_alloc() causes a double free when its_vpe_init() fails after successfully allocating at least one interrupt. This happens because its_vpe_irq_domain_free() frees the interrupts along with the area bitmap and the vprop_page and its_vpe_irq_domain_alloc() subsequently frees the area bitmap and the vprop_page again. Fix this by unconditionally invoking its_vpe_irq_domain_free() which handles all cases correctly and by removing the bitmap/vprop_page freeing from its_vpe_irq_domain_alloc(). [ tglx: Massaged change log ]

Affected products

  • Debian Debian Linux: version 10.0 only
  • Linux Linux Kernel: from 4.14, before 4.19.313 (fixed in 4.19.313); from 4.20, before 5.4.275 (fixed in 5.4.275); from 5.5, before 5.10.216 (fixed in 5.10.216); from 5.11, before 5.15.158 (fixed in 5.15.158); from 5.16, before 6.1.90 (fixed in 6.1.90); from 6.2, before 6.6.30 (fixed in 6.6.30); …

Published 2024-05-17. Last modified 2026-08-04.