CVE-2024-35983: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS bits_per() rounds up to the next power of two when passed a power of two. This causes crashes on some machines and configurations.
Affected products
- Linux Linux Kernel: from 5.4.274, before 5.4.275 (fixed in 5.4.275); from 5.10.215, before 5.10.216 (fixed in 5.10.216); from 5.15.154, before 5.15.158 (fixed in 5.15.158); from 6.1.84, before 6.1.90 (fixed in 6.1.90); from 6.6.24, before 6.6.30 (fixed in 6.6.30); from 6.7.12, before 6.8 (fixed in 6.8); …
Published 2024-05-20. Last modified 2026-06-17.