CVE-2024-35996
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-35996 affects the Linux kernel and involves CPU mitigations configuration. The vulnerability was discovered in May 2024 and relates to the re-enabling of CPU mitigations by default for non-X86 architectures. The issue arose from a recent commit that incorrectly turned mitigations off by default when SPECULATION_MITIGATIONS=n was set (Kernel Git).

Technical details

The vulnerability stems from a configuration mismatch where 'cpumitigations' is generic but was being controlled by the x86-specific 'SPECULATIONMITIGATIONS' setting. The fix involved renaming x86's configuration to CPU_MITIGATIONS, defining it in generic code, and forcing it on for all architectures except x86. This change allows x86 to manage mitigations that aren't strictly related to speculative execution (Kernel Git).

Impact

The vulnerability could potentially leave non-x86 architectures without proper CPU mitigations enabled by default, which could expose systems to various CPU-level security vulnerabilities. This affects the overall security posture of affected systems, particularly those running on non-x86 architectures (Kernel Git).

Mitigation and workarounds

The issue has been fixed by renaming the configuration option and ensuring proper default settings. The fix includes modifying the kernel configuration to use CPUMITIGATIONS instead of SPECULATIONMITIGATIONS, with appropriate defaults for all architectures. Systems should be updated to include this fix (Kernel Git, Debian LTS).

Community reactions

The vulnerability was reported by multiple kernel developers including Stephen Rothwell, Michael Ellerman, and Geert Uytterhoeven. The fix received acknowledgments from key kernel developers, including Josh Poimboeuf and Borislav Petkov from AMD (Kernel Git).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40300N/AN/A
  • Linux KernelLinux Kernel
  • perf-debuginfo
NoYesSep 11, 2025
CVE-2025-39791N/AN/A
  • Linux KernelLinux Kernel
  • kernel
NoNoSep 11, 2025
CVE-2025-39790N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-debug-modules-partner
NoNoSep 11, 2025
CVE-2025-39784N/AN/A
  • Linux KernelLinux Kernel
  • kernel-kdump
NoNoSep 11, 2025
CVE-2025-39782N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-debug
NoNoSep 11, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management