Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-26953

18
FAUCET Score

CVE-2024-26953 describes a page_pool leak vulnerability in the Linux kernel's ESP (Encapsulating Security Payload) protocol implementation. Specifically, when an skb (socket buffer) is reorganized during esp_output and its fragment pages originate from a page_pool, calling put_page on them incorrectly leads to a memory leak, eventually causing a system crash. This issue impacts Linux kernel versions and can be observed with IPsec and GRE forwarding. The vulnerability is rated Medium severity (CVSS 5.5) with a vector of AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. This indicates that a local attacker with low privileges can exploit this flaw with low attack complexity, resulting in high availability impact (system crash) but no confidentiality or integrity impact. There is currently no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness or attention at this time.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.14, < 6.6.24CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.7, < 6.7.12CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.8, < 6.8.3CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
13.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0023 is in the 60th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (16)

microsoftpatch availablevia msrc
Product: azl3 hyperv-daemons 6.6.22.1-2 on Azure Linux 3.0Fixed in: 6.6.35.1-1
microsoftpatch availablevia msrc
Product: cbl2 hyperv-daemons 5.15.164.1-1 on CBL Mariner 2.0Fixed in: 5.15.158.2-1
microsoftpatch availablevia msrc
Product: azl3 hyperv-daemons 6.6.35.1-1 on Azure Linux 3.0Fixed in: 6.6.35.1-1
microsoftpatch availablevia msrc
Product: 17328-16823Fixed in: 5.15.158.2-1
microsoftpatch availablevia msrc
Product: 19956-17086Fixed in: 5.15.158.2-1
microsoftpatch availablevia msrc
Product: 16989-17084Fixed in: 6.6.35.1-1
microsoftpatch availablevia msrc
Product: 17785-17084Fixed in: 6.6.35.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 5.15.167.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 5.15.167.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 5.15.158.2-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 5.15.158.2-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 6.6.35.1-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 6.6.35.1-1
microsoftpatch availablevia msrc
Product: cbl2 hyperv-daemons 5.15.158.2-1 on CBL Mariner 2.0Fixed in: 5.15.158.2-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-503.11.1.el9_5
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (4)

microsoft2024-Dec/CVE-2024-26953

CVE-2024-26953

Dec 10, 2024
microsoft2024-Oct/CVE-2024-26953

CVE-2024-26953

Oct 8, 2024
microsoft2024-May/CVE-2024-26953Moderate

net: esp: fix bad handling of pages from page_pool

May 14, 2024
redhatCVE-2024-26953Low

kernel: net: esp: fix bad handling of pages from page_pool

May 1, 2024

References

git.kernel.org / stable/c/1abb20a5f4b02fb3020f88456fc1e6069b3cdc45
Patch
git.kernel.org / stable/c/8291b4eac429c480386669444c6377573f5d8664
Patch
git.kernel.org / stable/c/c3198822c6cb9fb588e446540485669cc81c5d34
Patch
git.kernel.org / stable/c/f278ff9db67264715d0d50e3e75044f8b78990f4
Patch