CVE-2024-35815
Estado: ModificadaMedia (5.5)—
En el kernel de Linux, se resolvió la siguiente vulnerabilidad: fs/aio: verifique IOCB_AIO_RW antes de la conversión de struct aio_kiocb. El primer argumento kiocb_set_cancel_fn() puede apuntar a una estructura kiocb que no está incrustada dentro de struct aio_kiocb. Con el código actual, dependiendo del compilador, la lectura req->ki_ctx ocurre antes de la prueba IOCB_AIO_RW o después de esa prueba. Mueva la lectura req->ki_ctx de modo que se garantice que la prueba IOCB_AIO_RW se realice primero.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.25%
- Percentil entre todas las CVEs puntuadas: 15
- Fecha de la puntuación: 8/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- NVD-CWE-noinfo
Referencias
- https://git.kernel.org/stable/c/10ca82aff58434e122c7c757cf0497c335f993f3
- https://git.kernel.org/stable/c/18d5fc3c16cc317bd0e5f5dabe0660df415cadb7
- https://git.kernel.org/stable/c/396dbbc18963648e9d1a4edbb55cfe08fa374d50
- https://git.kernel.org/stable/c/5c43d0041e3a05c6c41c318b759fff16d2384596
- https://git.kernel.org/stable/c/94eb0293703ced580f05dfbe5a57da5931e9aee2
- https://git.kernel.org/stable/c/961ebd120565cb60cebe21cb634fbc456022db4a
- https://git.kernel.org/stable/c/a71cba07783abc76b547568b6452cd1dd9981410
- https://git.kernel.org/stable/c/c01ed748847fe8b810d86efc229b9e6c7fafa01e
- https://git.kernel.org/stable/c/10ca82aff58434e122c7c757cf0497c335f993f3
- https://git.kernel.org/stable/c/18d5fc3c16cc317bd0e5f5dabe0660df415cadb7
- https://git.kernel.org/stable/c/396dbbc18963648e9d1a4edbb55cfe08fa374d50
- https://git.kernel.org/stable/c/5c43d0041e3a05c6c41c318b759fff16d2384596
- https://git.kernel.org/stable/c/94eb0293703ced580f05dfbe5a57da5931e9aee2
- https://git.kernel.org/stable/c/961ebd120565cb60cebe21cb634fbc456022db4a
- https://git.kernel.org/stable/c/a71cba07783abc76b547568b6452cd1dd9981410
- https://git.kernel.org/stable/c/c01ed748847fe8b810d86efc229b9e6c7fafa01e
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html
- https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-35815",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-35815",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-05-20T14:12:56.685850Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "337b543e274fe7a8f47df3c8293cc6686ffa620f",
"lessThan": "10ca82aff58434e122c7c757cf0497c335f993f3",
"versionType": "git"
},
{
"status": "affected",
"version": "b4eea7a05ee0ab5ab0514421e6ba8c5d249cf942",
"lessThan": "396dbbc18963648e9d1a4edbb55cfe08fa374d50",
"versionType": "git"
},
{
"status": "affected",
"version": "ea1cd64d59f22d6d13f367d62ec6e27b9344695f",
"lessThan": "94eb0293703ced580f05dfbe5a57da5931e9aee2",
"versionType": "git"
},
{
"status": "affected",
"version": "d7b6fa97ec894edd02f64b83e5e72e1aa352f353",
"lessThan": "a71cba07783abc76b547568b6452cd1dd9981410",
"versionType": "git"
},
{
"status": "affected",
"version": "18f614369def2a11a52f569fe0f910b199d13487",
"lessThan": "18d5fc3c16cc317bd0e5f5dabe0660df415cadb7",
"versionType": "git"
},
{
"status": "affected",
"version": "e7e23fc5d5fe422827c9a43ecb579448f73876c7",
"lessThan": "c01ed748847fe8b810d86efc229b9e6c7fafa01e",
"versionType": "git"
},
{
"status": "affected",
"version": "1dc7d74fe456944a9b1c57bd776280249f441ac6",
"lessThan": "5c43d0041e3a05c6c41c318b759fff16d2384596",
"versionType": "git"
},
{
"status": "affected",
"version": "b820de741ae48ccf50dd95e297889c286ff4f760",
"lessThan": "961ebd120565cb60cebe21cb634fbc456022db4a",
"versionType": "git"
}
],
"programFiles": [
"fs/aio.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19.308",
"lessThan": "4.19.312",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.4.270",
"lessThan": "5.4.274",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.10.211",
"lessThan": "5.10.215",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.15.150",
"lessThan": "5.15.154",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.1.80",
"lessThan": "6.1.84",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.6.19",
"lessThan": "6.6.24",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.7.7",
"lessThan": "6.7.12",
"versionType": "semver"
}
],
"programFiles": [
"fs/aio.c"
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"affectedData": [
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-05-17T14:15:16.077",
"references": [
{
"url": "https://git.kernel.org/stable/c/10ca82aff58434e122c7c757cf0497c335f993f3",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/18d5fc3c16cc317bd0e5f5dabe0660df415cadb7",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/396dbbc18963648e9d1a4edbb55cfe08fa374d50",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5c43d0041e3a05c6c41c318b759fff16d2384596",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/94eb0293703ced580f05dfbe5a57da5931e9aee2",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/961ebd120565cb60cebe21cb634fbc456022db4a",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a71cba07783abc76b547568b6452cd1dd9981410",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c01ed748847fe8b810d86efc229b9e6c7fafa01e",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/10ca82aff58434e122c7c757cf0497c335f993f3",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://git.kernel.org/stable/c/18d5fc3c16cc317bd0e5f5dabe0660df415cadb7",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://git.kernel.org/stable/c/396dbbc18963648e9d1a4edbb55cfe08fa374d50",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://git.kernel.org/stable/c/5c43d0041e3a05c6c41c318b759fff16d2384596",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://git.kernel.org/stable/c/94eb0293703ced580f05dfbe5a57da5931e9aee2",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://git.kernel.org/stable/c/961ebd120565cb60cebe21cb634fbc456022db4a",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://git.kernel.org/stable/c/a71cba07783abc76b547568b6452cd1dd9981410",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://git.kernel.org/stable/c/c01ed748847fe8b810d86efc229b9e6c7fafa01e",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html",
"source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/aio: Check IOCB_AIO_RW before the struct aio_kiocb conversion\n\nThe first kiocb_set_cancel_fn() argument may point at a struct kiocb\nthat is not embedded inside struct aio_kiocb. With the current code,\ndepending on the compiler, the req->ki_ctx read happens either before\nthe IOCB_AIO_RW test or after that test. Move the req->ki_ctx read such\nthat it is guaranteed that the IOCB_AIO_RW test happens first."
},
{
"lang": "es",
"value": " En el kernel de Linux, se resolvió la siguiente vulnerabilidad: fs/aio: verifique IOCB_AIO_RW antes de la conversión de struct aio_kiocb. El primer argumento kiocb_set_cancel_fn() puede apuntar a una estructura kiocb que no está incrustada dentro de struct aio_kiocb. Con el código actual, dependiendo del compilador, la lectura req->ki_ctx ocurre antes de la prueba IOCB_AIO_RW o después de esa prueba. Mueva la lectura req->ki_ctx de modo que se garantice que la prueba IOCB_AIO_RW se realice primero."
}
],
"lastModified": "2026-06-17T07:35:28.057",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "017B5D47-54B0-4864-A4EC-76E944E9A963",
"versionEndExcluding": "4.19.312",
"versionStartIncluding": "4.19.308"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BB25F64F-5C99-4466-8D9A-1469885E86E7",
"versionEndExcluding": "5.4.274",
"versionStartIncluding": "5.4.270"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AFDEF5B7-531B-41B1-B5E4-44F31E00AF98",
"versionEndExcluding": "5.10.215",
"versionStartIncluding": "5.10.211"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2078FD3A-BAFD-4DF4-89B3-017B721C092B",
"versionEndExcluding": "5.15.154",
"versionStartIncluding": "5.15.150"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "487837EB-1F63-4418-B493-430A93B5F9A1",
"versionEndExcluding": "6.1.84",
"versionStartIncluding": "6.1.80"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8EC52D03-C451-4B7B-BE34-6735FCBB296A",
"versionEndExcluding": "6.6.24",
"versionStartIncluding": "6.6.19"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "976AF1BD-A716-495C-BDE4-0207737C6C4B",
"versionEndExcluding": "6.7.12",
"versionStartIncluding": "6.7.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.8:rc6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AEB9199B-AB8F-4877-8964-E2BA95B5F15C"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.8:rc7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C9B8A5CE-6D20-4C36-AC01-ACA4B70003A8"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "07B237A9-69A3-4A9C-9DA0-4E06BD37AE73"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}