In the Linux kernel, the following vulnerability has been resolved:
efi: fix panic in kdump kernel
Check if getnextvariable() is actually valid pointer before calling it. In kdump kernel this method is set to NULL that causes panic during the kexec-ed kernel boot.
Tested with QEMU and OVMF firmware.
[
{
"id": "CVE-2024-35800-256085d6",
"digest": {
"length": 232.0,
"function_hash": "243245088622606710571756658739709734112"
},
"signature_version": "v1",
"target": {
"file": "drivers/firmware/efi/efi.c",
"function": "generic_ops_supported"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7784135f134c13af17d9ffb39a57db8500bc60ff"
},
{
"id": "CVE-2024-35800-441c2d0b",
"digest": {
"length": 232.0,
"function_hash": "243245088622606710571756658739709734112"
},
"signature_version": "v1",
"target": {
"file": "drivers/firmware/efi/efi.c",
"function": "generic_ops_supported"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b9d103aca85f082a343b222493f3cab1219aaaf4"
},
{
"id": "CVE-2024-35800-47048828",
"digest": {
"length": 232.0,
"function_hash": "243245088622606710571756658739709734112"
},
"signature_version": "v1",
"target": {
"file": "drivers/firmware/efi/efi.c",
"function": "generic_ops_supported"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@62b71cd73d41ddac6b1760402bbe8c4932e23531"
},
{
"id": "CVE-2024-35800-4c076561",
"digest": {
"line_hashes": [
"40438142774934925156310734754019589400",
"221745955189983372019810210540345160113",
"336627503964537248818105267904755260477"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "drivers/firmware/efi/efi.c"
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9114ba9987506bcfbb454f6e68558d68cb1abbde"
},
{
"id": "CVE-2024-35800-5eb40673",
"digest": {
"line_hashes": [
"40438142774934925156310734754019589400",
"221745955189983372019810210540345160113",
"336627503964537248818105267904755260477"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "drivers/firmware/efi/efi.c"
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b9d103aca85f082a343b222493f3cab1219aaaf4"
},
{
"id": "CVE-2024-35800-b15874ba",
"digest": {
"line_hashes": [
"40438142774934925156310734754019589400",
"221745955189983372019810210540345160113",
"336627503964537248818105267904755260477"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "drivers/firmware/efi/efi.c"
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7784135f134c13af17d9ffb39a57db8500bc60ff"
},
{
"id": "CVE-2024-35800-bdd3ceda",
"digest": {
"line_hashes": [
"40438142774934925156310734754019589400",
"221745955189983372019810210540345160113",
"336627503964537248818105267904755260477"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "drivers/firmware/efi/efi.c"
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@090d2b4515ade379cd592fbc8931344945978210"
},
{
"id": "CVE-2024-35800-c5b5cbe9",
"digest": {
"length": 232.0,
"function_hash": "243245088622606710571756658739709734112"
},
"signature_version": "v1",
"target": {
"file": "drivers/firmware/efi/efi.c",
"function": "generic_ops_supported"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@090d2b4515ade379cd592fbc8931344945978210"
},
{
"id": "CVE-2024-35800-dae2de5e",
"digest": {
"length": 232.0,
"function_hash": "243245088622606710571756658739709734112"
},
"signature_version": "v1",
"target": {
"file": "drivers/firmware/efi/efi.c",
"function": "generic_ops_supported"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9114ba9987506bcfbb454f6e68558d68cb1abbde"
},
{
"id": "CVE-2024-35800-dfbeeca4",
"digest": {
"line_hashes": [
"40438142774934925156310734754019589400",
"221745955189983372019810210540345160113",
"336627503964537248818105267904755260477"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "drivers/firmware/efi/efi.c"
},
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@62b71cd73d41ddac6b1760402bbe8c4932e23531"
}
]