CVE-2024-35984: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: i2c: smbus: fix NULL function pointer dereference Baruch reported an OOPS when using the designware controller as target only. Target-only modes break the assumption of one transfer function always being available. Fix this by always checking the pointer in __i2c_transfer. [wsa: dropped the simplification in core-smbus to avoid theoretical regressions]
Affected products
- Linux Linux Kernel: from 3.19, before 4.19.313 (fixed in 4.19.313); from 4.20, before 5.4.275 (fixed in 5.4.275); from 5.5, before 5.10.216 (fixed in 5.10.216); from 5.11, before 5.15.158 (fixed in 5.15.158); from 5.16, before 6.1.90 (fixed in 6.1.90); from 6.2, before 6.6.30 (fixed in 6.6.30); …
Published 2024-05-20. Last modified 2026-06-17.