Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-40904

17
FAUCET Score

CVE-2024-40904 describes a CPU lockup vulnerability in the Linux kernel's cdc-wdm USB driver. This occurs due to excessive logging of error messages when the driver repeatedly resubmits interrupt URBs with a -EPROTO status, particularly when combined with dummy-hcd emulation. The vulnerability is rated Medium (CVSS 5.5) with a local attack vector and low attack complexity, leading to high availability impact (CPU lockup). There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.28, < 4.19.317CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.279CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.221CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.162CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.95CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.29%
Probability of exploitation in next 30 days
EPSS Percentile
21.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0029 is in the 78th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-553.22.1.rt7.363.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.22.1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-427.42.1.el9_4
View patch
oraclevendor investigatingvia oracle_oval
Product: cpe:/a:oracle:linux:6:10:UEKR4_ELS
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (2)

redhatCVE-2024-40904Moderate

kernel: USB: class: cdc-wdm: Fix CPU lockup caused by excessive log messages

Jul 12, 2024
oracleoval:com.oracle.ovmsa:def:20240016IMPORTANT

OVMSA-2024-0016: Unbreakable Enterprise kernel security update (IMPORTANT)

References

git.kernel.org / stable/c/02a4c0499fc3a02e992b4c69a9809912af372d94
Patch
git.kernel.org / stable/c/05b2cd6d33f700597e6f081b53c668a226a96d28
Patch
git.kernel.org / stable/c/217d1f44fff560b3995a685a60aa66e55a7f0f56
Patch
git.kernel.org / stable/c/22f00812862564b314784167a89f27b444f82a46
Patch
git.kernel.org / stable/c/53250b54c92fe087fd4b0c48f85529efe1ebd879
Patch
git.kernel.org / stable/c/72a3fe36cf9f0d030865e571f45a40f9c1e07e8a
Patch
git.kernel.org / stable/c/82075aff7ffccb1e72b0ac8aa349e473624d857c
Patch
git.kernel.org / stable/c/c0747d76eb05542b5d49f67069b64ef5ff732c6c
Patch
lists.debian.org / debian-lts-announce/2025/01/msg00001.html