Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-26764

13
FAUCET Score

CVE-2024-26764 is a low-severity vulnerability in the Linux kernel affecting Debian and other Linux distributions. It involves an improper restriction of the kiocb_set_cancel_fn() function, leading to a kernel warning when used with io_uring instead of libaio. The vulnerability has a CVSS score of 3.3, indicating a low impact on availability with no confidentiality or integrity concerns, and requires local access with low privileges. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.19.308CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.270CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.211CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.150CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.80CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.3LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
1.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.25%
Probability of exploitation in next 30 days
EPSS Percentile
16.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0025 is in the 60th percentile among its peer group of 1,511 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2024-26764Moderate

kernel: fs/aio: Restrict kiocb_set_cancel_fn() to I/O submitted via libaio

Apr 3, 2024

References

git.kernel.org / stable/c/18f614369def2a11a52f569fe0f910b199d13487
Patch
git.kernel.org / stable/c/1dc7d74fe456944a9b1c57bd776280249f441ac6
Patch
git.kernel.org / stable/c/337b543e274fe7a8f47df3c8293cc6686ffa620f
Patch
git.kernel.org / stable/c/b4eea7a05ee0ab5ab0514421e6ba8c5d249cf942
Patch
git.kernel.org / stable/c/b820de741ae48ccf50dd95e297889c286ff4f760
Patch
git.kernel.org / stable/c/d7b6fa97ec894edd02f64b83e5e72e1aa352f353
Patch
git.kernel.org / stable/c/e7e23fc5d5fe422827c9a43ecb579448f73876c7
Patch
git.kernel.org / stable/c/ea1cd64d59f22d6d13f367d62ec6e27b9344695f
Patch
lists.debian.org / debian-lts-announce/2024/06/msg00017.html
Mailing List
lists.debian.org / debian-lts-announce/2024/06/msg00020.html
Mailing List