CVE-2024-35935
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-35935 affects the Linux kernel's btrfs module, specifically in the send functionality. The vulnerability was discovered on May 19, 2024, and involves a path reference underflow issue in the iterate_inode_ref() function. The vulnerability affects various Linux kernel versions and distributions including Ubuntu, Debian, and other Linux-based systems (NVD).

Technical details

The vulnerability exists in the btrfs send module where a BUG_ON condition was used to handle path buffer failures. The issue occurs specifically in the iterate_inode_ref() function where improper error handling could potentially leak kernel addresses. The fix involves replacing the BUG_ON condition with proper error handling to prevent the buffer underflow and potential information disclosure (Kernel Commit).

Impact

If exploited, this vulnerability could lead to information disclosure by potentially leaking kernel addresses when the path buffer build fails. This could provide attackers with valuable information about the kernel's memory layout (NVD).

Exploitability

The vulnerability requires access to a system with the btrfs filesystem and the ability to trigger the path buffer build failure condition in the send operation. No known exploits in the wild have been reported at the time of assessment (CVE).

Mitigation and workarounds

The issue has been fixed in various Linux distributions through kernel updates. Ubuntu has released fixes for multiple versions including 24.04 LTS (6.8.0-38.38), 22.04 LTS (5.15.0-116.126), and 20.04 LTS (5.4.0-189.209). Debian has also released fixes in versions 5.10.234-1 for bullseye and 6.1.128-1 for bookworm (Ubuntu, Debian).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

linux: 6.1.90-1

Fixed

bullseye

linux: 5.10.216-1

Fixed

sid

linux: 6.8.9-1

Fixed

trixie

linux: 6.8.9-1

Fixed

SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93189HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-azure-fips
NoYesSep 17, 2026
CVE-2026-93188MEDIUM6.5
  • Linux Kernel logoLinux Kernel
  • linux-nvidia-tegra-5.15
NoYesSep 17, 2026
CVE-2026-93182NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-fips
NoYesSep 17, 2026
CVE-2026-93181NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-4.15
NoNoSep 17, 2026
CVE-2026-93174NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management