Bug 1224564 (CVE-2024-35983)

Summary: VUL-0: CVE-2024-35983: kernel: bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS
Product: [Novell Products] SUSE Security Incidents Reporter: SMASH SMASH <smash_bz>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: gianluca.gabrielli, jlee
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/406712/
Whiteboard:
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Comment 1 Joey Lee 2024-05-23 08:00:32 UTC
joeyli@linux-691t:/mnt/working/source_code-git/kernel-source> ./scripts/check-kernel-fix -s 0 CVE-2024-35983
5af385f5f4cd ("bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS") merged v6.9-rc7~37
Fixes: f2d5dcb48f7b ("bounds: support non-power-of-two CONFIG_NR_CPUS") merged v6.9-rc1~106^2~76
Security fix for CVE-2024-35983 bsc#1224564 with CVSS 0
Experts candidates: kernel@suse.de 
..............................
NO ACTION NEEDED: All relevant branches contain the fix!

Does not affect any branch. reset assigner
Comment 2 Andrea Mattiazzo 2024-06-07 12:17:23 UTC
All done, closing.