CVE-2024-35871
Linux Debian vulnerability analysis and mitigation

Overview

A vulnerability in the Linux kernel's RISC-V architecture implementation has been identified as CVE-2024-35871. The issue involves kernel gp (global pointer) leakage in the process handling code, where childregs represents the registers active for new threads in user context. This vulnerability was discovered in May 2024 and affects the Linux kernel's RISC-V architecture implementation (NVD).

Technical details

The vulnerability stems from improper handling of the global pointer (gp) register in kernel threads and user mode helper threads. For kernel threads, childregs->gp is never used since the kernel gp is not touched by switch_to. However, for user mode helper threads, the gp value can be observed in user space after execve or through other means. The vulnerability can be exploited through multiple vectors including kernel_execve, ptrace(PTRACE_GETREGSET), /proc//task//syscall, PERF_SAMPLE_REGS_USER, and various tracing infrastructure components (Kernel Commit).

Impact

The vulnerability allows user space processes to observe kernel addresses through various mechanisms, potentially leading to information disclosure. This is particularly concerning because it bypasses LOCKDOWN_PERF restrictions, as kernel addresses can be exposed via PERF_SAMPLE_REGS_USER which is normally permitted under LOCKDOWN_PERF (Kernel Commit).

Exploitability

The vulnerability can be exploited through at least five different methods: 1) kernel_execve execution, 2) ptrace attachment to user_mode_helper threads, 3) accessing /proc//task//syscall, 4) using PERF_SAMPLE_REGS_USER, and 5) through various tracing infrastructure components. The issue affects user mode helper threads that execute user processes, such as /sbin/init or when /proc/sys/kernel/core_pattern is a pipe (Kernel Commit).

Mitigation and workarounds

The vulnerability has been fixed by removing the gp_in_global register assignment and its usage in the process.c file. The fix was implemented through a patch that removes the global pointer leakage in the RISC-V process handling code. The patch has been merged into various Linux kernel versions and is available through distribution-specific updates (Ubuntu Security Notice, Debian LTS).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

linux: 6.1.85-1

Fixed

bullseye

linux: 5.10.216-1

Fixed

sid

linux: 6.8.9-1

Fixed

trixie

linux: 6.8.9-1

Fixed

SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-90776HIGH8.7
  • Grafana logoGrafana
  • grafana.src
NoNoSep 13, 2026
CVE-2026-90783HIGH8.5
  • Linux Debian logoLinux Debian
  • mkvtoolnix
NoNoSep 13, 2026
CVE-2026-90775HIGH7.1
  • Linux Debian logoLinux Debian
  • address-standardizer
NoNoSep 13, 2026
CVE-2026-90781MEDIUM4.8
  • Linux Debian logoLinux Debian
  • alsa-lib
NoNoSep 13, 2026
CVE-2026-90773LOW2.4
  • Linux Debian logoLinux Debian
  • rust-procs
NoNoSep 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management