Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-26733

16
FAUCET Score

CVE-2024-26733 is a Linux kernel vulnerability affecting the Address Resolution Protocol (ARP) component. Specifically, the arp_req_get() function, when processing an ioctl(SIOCGARP) request, can overflow a 14-byte buffer (arp_ha.sa_data) if the device address length (dev->addr_len) exceeds 22 bytes, potentially overwriting the subsequent arp_netmask field. This local vulnerability has a CVSS score of 5.5 (Medium), indicating a low attack complexity and requiring local privileges, with a potential impact of high availability loss. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.12, < 5.10.211CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.150CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.80CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.19CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.7, < 6.7.7CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 71st percentile among its peer group of 15,938 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

nodejspatch availablevia llm_extracted
View patch
pjsippatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: kernel-0:4.18.0-372.113.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: kernel-0:4.18.0-372.113.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: kernel-0:4.18.0-372.113.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-553.16.1.rt7.357.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-503.11.1.el9_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: kernel-0:5.14.0-427.61.1.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: kernel-0:4.18.0-477.67.1.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.16.1.el8_10
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (3)

nodejsllm-nodejs-302528ae26f0d946CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
pjsipllm-pjsip-7ba3ec379210ac70CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
redhatCVE-2024-26733Moderate

kernel: arp: Prevent overflow in arp_req_get().

Apr 3, 2024

References

git.kernel.org / stable/c/3ab0d6f8289ba8402ca95a9fc61a34909d5e1f3a
Patch
git.kernel.org / stable/c/97eaa2955db4120ce6ec2ef123e860bc32232c50
Patch
git.kernel.org / stable/c/a3f2c083cb575d80a7627baf3339e78fedccbb91
Patch
git.kernel.org / stable/c/a7d6027790acea24446ddd6632d394096c0f4667
Patch
git.kernel.org / stable/c/dbc9b22d0ed319b4e29034ce0a3fe32a3ee2c587
Patch
git.kernel.org / stable/c/f119f2325ba70cbfdec701000dcad4d88805d5b0
Patch
lists.debian.org / debian-lts-announce/2024/06/msg00017.html
Mailing List
security.netapp.com / advisory/ntap-20241101-0013
Third Party Advisory