{"id":"DEBIAN-CVE-2024-35855","details":"In the Linux kernel, the following vulnerability has been resolved:  mlxsw: spectrum_acl_tcam: Fix possible use-after-free during activity update  The rule activity update delayed work periodically traverses the list of configured rules and queries their activity from the device.  As part of this task it accesses the entry pointed by 'ventry-\u003eentry', but this entry can be changed concurrently by the rehash delayed work, leading to a use-after-free [1].  Fix by closing the race and perform the activity query under the 'vregion-\u003elock' mutex.  [1] BUG: KASAN: slab-use-after-free in mlxsw_sp_acl_tcam_flower_rule_activity_get+0x121/0x140 Read of size 8 at addr ffff8881054ed808 by task kworker/0:18/181  CPU: 0 PID: 181 Comm: kworker/0:18 Not tainted 6.9.0-rc2-custom-00781-gd5ab772d32f7 #2 Hardware name: Mellanox Technologies Ltd. MSN3700/VMOD0005, BIOS 5.11 01/06/2019 Workqueue: mlxsw_core mlxsw_sp_acl_rule_activity_update_work Call Trace:  \u003cTASK\u003e  dump_stack_lvl+0xc6/0x120  print_report+0xce/0x670  kasan_report+0xd7/0x110  mlxsw_sp_acl_tcam_flower_rule_activity_get+0x121/0x140  mlxsw_sp_acl_rule_activity_update_work+0x219/0x400  process_one_work+0x8eb/0x19b0  worker_thread+0x6c9/0xf70  kthread+0x2c9/0x3b0  ret_from_fork+0x4d/0x80  ret_from_fork_asm+0x1a/0x30  \u003c/TASK\u003e  Allocated by task 1039:  kasan_save_stack+0x33/0x60  kasan_save_track+0x14/0x30  __kasan_kmalloc+0x8f/0xa0  __kmalloc+0x19c/0x360  mlxsw_sp_acl_tcam_entry_create+0x7b/0x1f0  mlxsw_sp_acl_tcam_vchunk_migrate_all+0x30d/0xb50  mlxsw_sp_acl_tcam_vregion_rehash_work+0x157/0x1300  process_one_work+0x8eb/0x19b0  worker_thread+0x6c9/0xf70  kthread+0x2c9/0x3b0  ret_from_fork+0x4d/0x80  ret_from_fork_asm+0x1a/0x30  Freed by task 1039:  kasan_save_stack+0x33/0x60  kasan_save_track+0x14/0x30  kasan_save_free_info+0x3b/0x60  poison_slab_object+0x102/0x170  __kasan_slab_free+0x14/0x30  kfree+0xc1/0x290  mlxsw_sp_acl_tcam_vchunk_migrate_all+0x3d7/0xb50  mlxsw_sp_acl_tcam_vregion_rehash_work+0x157/0x1300  process_one_work+0x8eb/0x19b0  worker_thread+0x6c9/0xf70  kthread+0x2c9/0x3b0  ret_from_fork+0x4d/0x80  ret_from_fork_asm+0x1a/0x30","modified":"2026-09-15T09:03:07.433343922Z","published":"2024-05-17T15:15:22.677Z","upstream":["CVE-2024-35855"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-35855"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.90-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-35855.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.8.9-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-35855.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.8.9-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-35855.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}