Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-40943

16
FAUCET Score

CVE-2024-40943 is a race condition vulnerability in the OCFS2 filesystem of the Linux kernel. It occurs when hole punching operations race with asynchronous I/O (AIO) and direct I/O (DIO), leading to on-disk corruption and rendering the filesystem read-only. The vulnerability has a CVSS score of 4.7 (Medium), indicating a local attack vector with high attack complexity, requiring low privileges, and resulting in high availability impact. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.23, < 4.19.317CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.279CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.221CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.162CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.95CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.7MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
8.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0019 is in the 43rd percentile among its peer group of 1,297 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

oraclevendor investigatingvia oracle_oval
Product: cpe:/a:oracle:linux:6:10:UEKR4_ELS

Vendor Advisories (2)

redhatCVE-2024-40943Low

kernel: ocfs2: fix races between hole punching and AIO+DIO

Jul 12, 2024
oracleoval:com.oracle.ovmsa:def:20240016IMPORTANT

OVMSA-2024-0016: Unbreakable Enterprise kernel security update (IMPORTANT)

References

git.kernel.org / stable/c/050ce8af6838c71e872e982b50d3f1bec21da40e
Patch
git.kernel.org / stable/c/117b9c009b72a6c2ebfd23484354dfee2d9570d2
Patch
git.kernel.org / stable/c/38825ff9da91d2854dcf6d9ac320a7e641e10f25
Patch
git.kernel.org / stable/c/3c26b5d21b1239e9c7fd31ba7d9b2d7bdbaa68d9
Patch
git.kernel.org / stable/c/3c361f313d696df72f9bccf058510e9ec737b9b1
Patch
git.kernel.org / stable/c/952b023f06a24b2ad6ba67304c4c84d45bea2f18
Patch
git.kernel.org / stable/c/e8e2db1adac47970a6a9225f3858e9aa0e86287f
Patch
git.kernel.org / stable/c/ea042dc2bea19d72e37c298bf65a9c341ef3fff3
Patch
lists.debian.org / debian-lts-announce/2025/01/msg00001.html