Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-40959

18
FAUCET Score

CVE-2024-40959 is a null pointer dereference vulnerability in the Linux kernel's xfrm6 IPv6 transformation subsystem, specifically within the xfrm6_get_saddr() function. This flaw occurs because ip6_dst_idev() can return a NULL value, which xfrm6_get_saddr() fails to properly handle, leading to a general protection fault. The vulnerability affects the Linux kernel and has a CVSSv3.1 score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring low privileges, and primarily impacting system availability. There is currently no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB, and it has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.12, < 4.19.317CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.279CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.221CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.162CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.96CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.28%
Probability of exploitation in next 30 days
EPSS Percentile
19.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0028 is in the 75th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-553.22.1.rt7.363.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.22.1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-427.40.1.el9_4
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2024-40959Moderate

kernel: xfrm6: check ip6_dst_idev() return value in xfrm6_get_saddr()

Jul 12, 2024

References

cert-portal.siemens.com / productcert/html/ssa-265688.html
cert-portal.siemens.com / productcert/html/ssa-355557.html
cert-portal.siemens.com / productcert/html/ssa-398330.html
cert-portal.siemens.com / productcert/html/ssa-613116.html
git.kernel.org / stable/c/20427b85781aca0ad072851f6907a3d4b2fed8d1
Patch
git.kernel.org / stable/c/600a62b4232ac027f788c3ca395bc2333adeaacf
Patch
git.kernel.org / stable/c/83c02fb2cc0afee5bb53cddf3f34f045f654ad6a
Patch
git.kernel.org / stable/c/9f30f1f1a51d91e19f5a09236bb0b59e6a07ad08
Patch
git.kernel.org / stable/c/c71761292d4d002a8eccb57b86792c4e3b3eb3c7
Patch
git.kernel.org / stable/c/caf0bec84c62fb1cf6f7c9f0e8c857c87f8adbc3
Patch
git.kernel.org / stable/c/d46401052c2d5614da8efea5788532f0401cb164
Patch
git.kernel.org / stable/c/f897d7171652fcfc76d042bfec798b010ee89e41
Patch
lists.debian.org / debian-lts-announce/2025/01/msg00001.html