Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-38599

19
FAUCET Score

CVE-2024-38599 is a vulnerability in the Linux kernel's JFFS2 filesystem, specifically affecting how extended attribute (xattr) nodes are handled. It occurs when an xattr node exceeds the size of an eraseblock, causing it to overwrite subsequent data and corrupt the filesystem. This can lead to various errors, including data corruption and Kernel Address Sanitizer (KASAN) crashes. The vulnerability has a CVSS score of 7.1 (HIGH), indicating a significant risk. An attacker with local access (AV:L, PR:L) could exploit this with low attack complexity (AC:L) to cause a denial of service (A:H) or potentially disclose sensitive information (C:H) due to filesystem corruption. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, suggesting low public awareness of this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.18, < 4.19.316CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.278CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.219CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.161CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.93CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 49th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

codesyspatch availablevia llm_extracted
View patch
esphomepatch availablevia llm_extracted
View patch
oraclevendor investigatingvia oracle_oval
Product: cpe:/a:oracle:linux:6:10:UEKR4_ELS

Vendor Advisories (4)

codesysllm-codesys-fe85e88fbae25bb9CRITICAL

HP ThinPro 8.1 SP7 Security Updates

Jun 3, 2025
esphomellm-esphome-ed450ce9fd6a7380CRITICAL

HP ThinPro 8.1 SP7 Security Updates

Jun 3, 2025
redhatCVE-2024-38599Moderate

kernel: jffs2: prevent xattr node from overflowing the eraseblock

Jun 19, 2024
oracleoval:com.oracle.ovmsa:def:20240016IMPORTANT

OVMSA-2024-0016: Unbreakable Enterprise kernel security update (IMPORTANT)

References

cert-portal.siemens.com / productcert/html/ssa-265688.html
git.kernel.org / stable/c/2904e1d9b64f72d291095e3cbb31634f08788b11
Patch
git.kernel.org / stable/c/526235dffcac74c7823ed504dfac4f88d84ba5df
Patch
git.kernel.org / stable/c/8d431391320c5c5398ff966fb3a95e68a7def275
Patch
git.kernel.org / stable/c/978a12c91b38bf1a213e567f3c20e2beef215f07
Patch
git.kernel.org / stable/c/a1d21bcd78cf4a4353e1e835789429c6b76aca8b
Patch
git.kernel.org / stable/c/af82d8d2179b7277ad627c39e7e0778f1c86ccdb
Patch
git.kernel.org / stable/c/c6854e5a267c28300ff045480b5a7ee7f6f1d913
Patch
git.kernel.org / stable/c/f06969df2e40ab1dc8f4364a5de967830c74a098
Patch
git.kernel.org / stable/c/f0eea095ce8c959b86e1e57fe36ca4fea5ae54f8
Patch
lists.debian.org / debian-lts-announce/2024/06/msg00020.html