Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-38596

16
FAUCET Score

CVE-2024-38596 describes a data-race condition in the Linux kernel's af_unix component, specifically within the unix_release_sock and unix_stream_sendmsg functions. This vulnerability affects Linux kernel versions and can lead to a KCSAN splat, indicating a potential denial of service. It has a CVSS score of 4.7 (Medium) with a local attack vector and high attack complexity, potentially causing high availability impact. There is no evidence of active exploitation, public exploit code, or significant media coverage, though it has received some community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.13, < 4.19.316CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.278CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.219CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.161CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.93CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.7MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.19%
Probability of exploitation in next 30 days
EPSS Percentile
8.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0019 is in the 44th percentile among its peer group of 1,297 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

codesyspatch availablevia llm_extracted
View patch
esphomepatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: kernel-0:4.18.0-372.113.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: kernel-0:4.18.0-372.113.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: kernel-0:4.18.0-372.113.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: kernel-0:4.18.0-477.70.1.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-553.16.1.rt7.357.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: kernel-0:5.14.0-284.75.1.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: kernel-rt-0:5.14.0-284.75.1.rt14.360.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: kernel-0:5.14.0-427.44.1.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-503.11.1.el9_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.16.1.el8_10
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (3)

codesysllm-codesys-fe85e88fbae25bb9CRITICAL

HP ThinPro 8.1 SP7 Security Updates

Jun 3, 2025
esphomellm-esphome-ed450ce9fd6a7380CRITICAL

HP ThinPro 8.1 SP7 Security Updates

Jun 3, 2025
redhatCVE-2024-38596Low

kernel: af_unix: Fix data races in unix_release_sock/unix_stream_sendmsg

Jun 19, 2024

References

cert-portal.siemens.com / productcert/html/ssa-265688.html
cert-portal.siemens.com / productcert/html/ssa-398330.html
cert-portal.siemens.com / productcert/html/ssa-613116.html
git.kernel.org / stable/c/0688d4e499bee3f2749bca27329bd128686230cb
Patch
git.kernel.org / stable/c/4d51845d734a4c5d079e56e0916f936a55e15055
Patch
git.kernel.org / stable/c/540bf24fba16b88c1b3b9353927204b4f1074e25
Patch
git.kernel.org / stable/c/8299e4d778f664b31b67cf4cf3d5409de2ecb92c
Patch
git.kernel.org / stable/c/9aa8773abfa0e954136875b4cbf2df4cf638e8a5
Patch
git.kernel.org / stable/c/a4c88072abcaca593cefe70f90e9d3707526e8f9
Patch
git.kernel.org / stable/c/a52fa2addfcccc2c5a0217fd45562605088c018b
Patch
git.kernel.org / stable/c/de6641d213373fbde9bbdd7c4b552254bc9f82fe
Patch
git.kernel.org / stable/c/fca6072e1a7b1e709ada5604b951513b89b4bd0a
Patch
lists.debian.org / debian-lts-announce/2024/06/msg00020.html