CVE-2024-35924
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-35924 affects the Linux kernel's USB Type-C UCSI (USB Type-C Connector System Software Interface) implementation. The vulnerability was discovered and disclosed on May 19, 2024, and involves a potential buffer overflow issue in the MESSAGE_IN region handling for UCSI versions prior to 2.0. The vulnerability specifically affects systems running Linux kernel versions that implement UCSI 1.2, where the MESSAGE_IN region size was limited to 16 bytes, compared to 256 bytes in UCSI 2.0 (Kernel Git).

Technical details

The vulnerability stems from a size mismatch between UCSI versions 1.2 and 2.0, where the MESSAGE_IN region size was increased from 16 to 256 bytes. On systems running UCSI v1.2, reading larger sizes could potentially cause buffer overflows. The fix implements a mechanism to use the read UCSI version to truncate read sizes on UCSI v1.2 systems, ensuring that buffer reads are limited to the appropriate size of 16 bytes (Kernel Git).

Impact

The vulnerability could potentially lead to buffer overflows when reading from the MESSAGE_IN region on systems running UCSI v1.2. This could affect USB Type-C functionality and potentially lead to system stability issues or security vulnerabilities on affected systems (Ubuntu Security).

Exploitability

There are no reported instances of this vulnerability being exploited in the wild. The vulnerability requires local access to the system and interaction with the USB subsystem to potentially trigger the overflow condition (NVD).

Mitigation and workarounds

The vulnerability has been patched in various Linux kernel versions. Ubuntu has released fixes for version 24.04 LTS (noble) with kernel version 6.8.0-38.38, and similar fixes have been implemented in other distributions. Users are advised to update their systems to the latest kernel version that includes the fix (Ubuntu Security).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

linux

Affected

bullseye

linux

Affected

sid

linux: 6.8.9-1

Fixed

trixie

linux: 6.8.9-1

Fixed

SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93189HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-azure-fips
NoYesSep 17, 2026
CVE-2026-93188MEDIUM6.5
  • Linux Kernel logoLinux Kernel
  • linux-nvidia-tegra-5.15
NoYesSep 17, 2026
CVE-2026-93182NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-fips
NoYesSep 17, 2026
CVE-2026-93181NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-4.15
NoNoSep 17, 2026
CVE-2026-93174NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management