Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-40927

22
FAUCET Score

CVE-2024-40927 is a use-after-free vulnerability in the Linux kernel's xHCI driver, specifically impacting USB stream handling. It affects the Linux kernel and can lead to system crashes or memory corruption. The vulnerability has a CVSSv3 score of 7.8 (High), indicating that a local attacker with low privileges can achieve high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, and no public exploit code or significant community discussion has been observed.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.35, < 5.15.162CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.95CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.35CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.7, < 6.9.6CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
6.10CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.10:rc1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.29%
Probability of exploitation in next 30 days
EPSS Percentile
21.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0029 is in the 58th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-553.16.1.rt7.357.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.16.1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-427.35.1.el9_4
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2024-40927Moderate

kernel: xhci: Handle TD clearing for multiple streams case

Jul 12, 2024

References

git.kernel.org / stable/c/26460c1afa311524f588e288a4941432f0de6228
Patch
git.kernel.org / stable/c/5ceac4402f5d975e5a01c806438eb4e554771577
Patch
git.kernel.org / stable/c/61593dc413c3655e4328a351555235bc3089486a
Patch
git.kernel.org / stable/c/633f72cb6124ecda97b641fbc119340bd88d51a9
Patch
git.kernel.org / stable/c/949be4ec5835e0ccb3e2a8ab0e46179cb5512518
Patch
lists.debian.org / debian-lts-announce/2025/01/msg00001.html