Answer in brief
CVE-2024-35962 records a Unknown severity vulnerability in netfilter: complete validation of user input. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/RUGGEDCOM RST2428P (generic), Siemens/SCALANCE XCM-/XRM-/XCH-/XRH-300 family (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/RUGGEDCOM RST2428P (generic), Siemens/SCALANCE XCM-/XRM-/XCH-/XRH-300 family (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0f038242b77ddfc505bf4163d4904c1abd2e74d6 <cf4bc359b76144a3dd55d7c09464ef4c5f2b2b05 || >=440e948cf0eff32cfe322dcbca3f2525354b159b <97dab36e57c64106e1c8ebd66cbf0d2d1e52d6b7 || >=18aae2cb87e5faa9c5bd865260ceadac60d5a6c5 <c760089aa98289b4b88a7ff5a62dd92845adf223 || >=81d51b9b7c95e791ba3c1a2dd77920a9d3b3f525 <89242d9584c342cb83311b598d9e6b82572eadf8 || >=58f2bfb789e6bd3bc24a2c9c1580f3c67aec3018 <562b7245131f6e9f1d280c8b5a8750f03edfc05c || >=0c83842df40f86e529db6842231154772c20edcc <65acf6e0501ac8880a4f73980d01b5d27648b956 | cf4bc359b76144a3dd55d7c09464ef4c5f2b2b05, 97dab36e57c64106e1c8ebd66cbf0d2d1e52d6b7, c760089aa98289b4b88a7ff5a62dd92845adf223, 89242d9584c342cb83311b598d9e6b82572eadf8, 562b7245131f6e9f1d280c8b5a8750f03edfc05c, 65acf6e0501ac8880a4f73980d01b5d27648b956 |
| Linux/Linuxgeneric | >=5.10.215 <5.10.216 || >=5.15.154 <5.15.156 || >=6.1.85 <6.1.87 || >=6.6.26 <6.6.28 || >=6.8.5 <6.8.7 | 5.10.216, 5.15.156, 6.1.87, 6.6.28, 6.8.7 |
| Siemens/RUGGEDCOM RST2428Pgeneric | >=0 <V3.1 | V3.1 |
| Siemens/SCALANCE XCM-/XRM-/XCH-/XRH-300 familygeneric | >=0 <V3.1 | V3.1 |
| Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystemgeneric | >=0 <* | * |
Published upstream
May 20, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: complete validation of user input In my recent commit, I missed that do_replace() handlers use copy_from_sockptr() (which I fixed), followed by unsafe copy_from_sockptr_offset() calls. In all functions, we can perform the @optlen validation before even calling xt_alloc_table_info() with the following check: if ((u64)optlen < (u64)tmp.size + sizeof(tmp)) return -EINVAL;
Quoted source text, attributed separately from HOL analysis.