CVE-2024-35960 | net/mlx5: Properly link new fs rules into the tree

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Properly link new fs rules into the tree Previously, add_rule_fg would only add newly created rules from the handle into the tree when they had a refcount of 1. On the other hand, create_flow_handle tries hard to find and reference already existing identical rules instead of creating new ones. These two behaviors can result in a situation where create_flow_handle 1) creates a new rule and references it, then 2) in a subsequent step during the same handle creation references it again, resulting in a rule with a refcount of 2 that is not linked into the tree, will have a NULL parent and root and will result in a crash when the flow group is deleted because del_sw_hw_rule, invoked on rule deletion, assumes node->parent is != NULL. This happened in the wild, due to another bug related to incorrect handling of duplicate pkt_reformat ids, which lead to the code in create_flow_handle incorrectly referencing a just-added rule in the same flow handle, resulting in the problem described above. Full details are at [1]. This patch changes add_rule_fg to add new rules without parents into the tree, properly initializing them and avoiding the crash. This makes it more consistent with how rules are added to an FTE in create_flow_handle.

Published: 2024-05-20 Last update: 2026-05-12 Assigner: 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67

Conclusion & alert: CVE-2024-35960 is rated High Risk (67.2/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 2.68%). Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2024-35960

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-03 1.99% 2.68% +0.69%
2 2026-05-12 1.75% 1.99% +0.24%
3 2025-11-21 1.75%

Full EPSS history (13 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2024-35960

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
9.1 3.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 5.2 134c704f-9b21-4f2e-91b3-4a467353bcc0

Weakness enumeration for CVE-2024-35960

GitHub Security Advisory for CVE-2024-35960

GHSA-hgw6-479w-27jj · Severity: critical — In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Properly link new...

OS Trackers for CVE-2024-35960

vendor priority summary link
debian not yet assigned CVE-2024-35960 not yet assigned priority: Debian including 1 source packages (linux), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2024-35960
redhat medium https://access.redhat.com/security/cve/CVE-2024-35960
suse medium https://www.suse.com/security/cve/CVE-2024-35960/
ubuntu medium CVE-2024-35960 medium priority: Ubuntu including 160 source packages (linux, linux-allwinner-5.19, …), 1686 status rows across 11 suites (bionic, focal, jammy, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): DNE 1267, released 196, ignored 145, not-affected 78. https://ubuntu.com/security/CVE-2024-35960

Affected software / configurations for CVE-2024-35960

Vendor Product Version Raw CPE
linux linux_kernel >= 4.10, < 4.19.313 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
linux linux_kernel >= 4.20, < 5.4.275 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
linux linux_kernel >= 5.5, < 5.10.216 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
linux linux_kernel >= 5.11, < 5.15.156 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
linux linux_kernel >= 5.16, < 6.1.87 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
linux linux_kernel >= 6.2, < 6.6.28 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
linux linux_kernel >= 6.7, < 6.8.7 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
linux linux_kernel 6.9 cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:*
linux linux_kernel 6.9 cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*
linux linux_kernel 6.9 cpe:2.3:o:linux:linux_kernel:6.9:rc3:*:*:*:*:*:*
debian debian_linux 10.0 cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

References for CVE-2024-35960

URL Tags
https://git.kernel.org/stable/c/1263b0b26077b1183c3c45a0a2479573a351d423 Patch
https://git.kernel.org/stable/c/2e8dc5cffc844dacfa79f056dea88002312f253f Patch
https://git.kernel.org/stable/c/3d90ca9145f6b97b38d0c2b6b30f6ca6af9c1801 Patch
https://git.kernel.org/stable/c/5cf5337ef701830f173b4eec00a4f984adeb57a0 Patch
https://git.kernel.org/stable/c/7aaee12b804c5e0374e7b132b6ec2158ff33dd64 Patch
https://git.kernel.org/stable/c/7c6782ad4911cbee874e85630226ed389ff2e453 Patch
https://git.kernel.org/stable/c/adf67a03af39095f05d82050f15813d6f700159d Patch
https://git.kernel.org/stable/c/de0139719cdda82806a47580ca0df06fc85e0bd2 Patch
https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html Mailing List Third Party Advisory
https://cert-portal.siemens.com/productcert/html/ssa-265688.html
https://cert-portal.siemens.com/productcert/html/ssa-613116.html
cvelogic Threat Intelligence