
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-35943 affects the Linux kernel's power management domain (pmdomain) subsystem, specifically in the TI OMAP PRM (Power and Reset Manager) driver. The vulnerability was discovered and disclosed on May 19, 2024, and involves a missing null pointer check in the omap_prm_domain_init function. This issue affects various Linux kernel versions and distributions including Ubuntu and Debian systems (NVD, Ubuntu).
The vulnerability exists in the omap_prm_domain_init function within the TI OMAP PRM driver. The issue occurs because the function fails to check the return value of devm_kasprintf(), which can return NULL upon memory allocation failure. The fix involves adding a null pointer check to ensure the allocation was successful before proceeding with the pointer usage (Kernel Commit).
If exploited, this vulnerability could lead to system instability or potential denial of service conditions when the memory allocation fails in the OMAP PRM driver initialization. The impact is limited to systems using the TI OMAP hardware platform (NVD).
The vulnerability requires local access to a system using the affected TI OMAP hardware. No known exploits have been reported in the wild at the time of assessment (NVD).
The vulnerability has been fixed in multiple Linux kernel versions. Ubuntu has released patches for version 6.8.0-38.38 in noble (24.04 LTS) and other affected versions. Debian has also included fixes in their security updates. Users are advised to update their systems to the patched versions (Ubuntu, Debian).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."