Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-38541

30
FAUCET Score

CVE-2024-38541 is a critical buffer overflow vulnerability in the Linux kernel's of_modalias() function, affecting Linux systems. This flaw allows an attacker to cause a negative length value and out-of-bounds write if the buffer is too small for the initial snprintf() call. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk with network-based attack vector, low attack complexity, and high impacts on confidentiality, integrity, and availability. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness and potential future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.14, < 5.4.294CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.238CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.182CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.136CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.33CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.48%
Probability of exploitation in next 30 days
EPSS Percentile
71.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0148 is in the 58th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

autodeskpatch availablevia llm_extracted
View patch
codesyspatch availablevia llm_extracted
View patch
esphomepatch availablevia llm_extracted
View patch
freepbxpatch availablevia llm_extracted
View patch
honeywellpatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-553.27.1.rt7.368.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: kernel-0:5.14.0-427.47.1.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-570.12.1.el9_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.27.1.el8_10
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (7)

autodeskllm-autodesk-c365b674a2ff5a3aCRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
honeywellllm-honeywell-c82b5cfda9df97a3CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
freepbxllm-freepbx-e54908c7967265f6CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
esphomellm-esphome-ed450ce9fd6a7380CRITICAL

HP ThinPro 8.1 SP7 Security Updates

Jun 3, 2025
codesysllm-codesys-fe85e88fbae25bb9CRITICAL

HP ThinPro 8.1 SP7 Security Updates

Jun 3, 2025
redhatCVE-2024-38541Moderate

kernel: of: module: add buffer overflow check in of_modalias()

Jun 19, 2024
microsoft2024-Jun/CVE-2024-38541

of: module: add buffer overflow check in of_modalias()

Jun 11, 2024

References

git.kernel.org / stable/c/0b0d5701a8bf02f8fee037e81aacf6746558bfd6
Patch
git.kernel.org / stable/c/46795440ef2b4ac919d09310a69a404c5bc90a88
Patch
git.kernel.org / stable/c/5d59fd637a8af42b211a92b2edb2474325b4d488
Patch
git.kernel.org / stable/c/733e62786bdf1b2b9dbb09ba2246313306503414
Patch
git.kernel.org / stable/c/c7f24b7d94549ff4623e8f41ea4d9f5319bd8ac8
Patch
git.kernel.org / stable/c/cf7385cb26ac4f0ee6c7385960525ad534323252
Patch
git.kernel.org / stable/c/e45b69360a63165377b30db4a1dfddd89ca18e9a
Patch
git.kernel.org / stable/c/ee332023adfd5882808f2dabf037b32d6ce36f9e
Patch
lists.debian.org / debian-lts-announce/2025/05/msg00045.html
lists.debian.org / debian-lts-announce/2025/10/msg00007.html