Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-39475

17
FAUCET Score

CVE-2024-39475 is a medium-severity vulnerability affecting the Linux kernel's fbdev savage driver. It stems from an unhandled error return when savagefb_check_var fails, specifically when the pixclock value is zero, leading to a divide-by-zero error. This local vulnerability (CVSS 5.5) requires low privileges and local access, resulting in high availability impact (system crash) but no confidentiality or integrity impact. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.19, < 4.19.316CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.4, < 5.4.278CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.10, < 5.10.219CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.15, < 5.15.161CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.1, < 6.1.94CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
13.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0023 is in the 61st percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (14)

microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.22.1-2 on Azure Linux 3.0Fixed in: 6.6.35.1-5
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 5.15.162.2-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 6.6.35.1-5
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 6.6.35.1-5
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 5.15.162.2-1
microsoftpatch availablevia msrc
Product: 17233-16823Fixed in: 5.15.162.2-1
microsoftpatch availablevia msrc
Product: 19702-17086Fixed in: 5.15.162.2-1
microsoftpatch availablevia msrc
Product: 17292-17086Fixed in: 5.15.162.2-1
microsoftpatch availablevia msrc
Product: 17671-17084Fixed in: -
microsoftpatch availablevia msrc
Product: 16839-17084Fixed in: 6.6.35.1-5
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.162.2-1 on CBL Mariner 2.0Fixed in: 5.15.162.2-1
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.160.1-1 on CBL Mariner 2.0Fixed in: 5.15.162.2-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.35.1-5 on Azure Linux 3.0Fixed in: -
oraclevendor investigatingvia oracle_oval
Product: cpe:/a:oracle:linux:6:10:UEKR4_ELS

Vendor Advisories (4)

microsoft2024-Sep/CVE-2024-39475

CVE-2024-39475

Sep 10, 2024
microsoft2024-Jul/CVE-2024-39475Moderate

fbdev: savage: Handle err return when savagefb_check_var failed

Jul 9, 2024
redhatCVE-2024-39475Low

kernel: fbdev: savage: Handle err return when savagefb_check_var failed

Jul 5, 2024
oracleoval:com.oracle.ovmsa:def:20240016IMPORTANT

OVMSA-2024-0016: Unbreakable Enterprise kernel security update (IMPORTANT)

References

git.kernel.org / stable/c/32f92b0078ebf79dbe4827288e0acb50d89d3d5b
Mailing ListPatch
git.kernel.org / stable/c/4b2c67e30b4e1d2ae19dba8b8e8f3b5fd3cf8089
Mailing ListPatch
git.kernel.org / stable/c/5f446859bfa46df0ffb34149499f48a2c2d8cd95
Mailing ListPatch
git.kernel.org / stable/c/6ad959b6703e2c4c5d7af03b4cfd5ff608036339
Mailing ListPatch
git.kernel.org / stable/c/86435f39c18967cdd937d7a49ba539cdea7fb547
Mailing ListPatch
git.kernel.org / stable/c/b8385ff814ca4cb7e63789841e6ec2a14c73e1e8
Mailing ListPatch
git.kernel.org / stable/c/be754cbd77eaf2932408a4e18532e4945274a5c7
Mailing ListPatch
git.kernel.org / stable/c/edaa57480b876e8203b51df7c3d14a51ea6b09e3
Mailing ListPatch