Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-40968

17
FAUCET Score

CVE-2024-40968 addresses a vulnerability in the Linux kernel, specifically impacting MIPS Octeon processors. This flaw allows a local attacker to trigger a kernel panic, leading to a denial of service, by attempting to access the configuration space of peripheral PCIe devices after a surprise link down event. Rated Medium (CVSS 5.5), the vulnerability requires local access and low privileges, with no user interaction needed. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.19.317CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.279CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.221CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.162CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.96CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
21.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 78th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2024-40968Low

kernel: MIPS: Octeon: Add PCIe link status check

Jul 12, 2024

References

git.kernel.org / stable/c/1c33fd17383f48f679186c54df78542106deeaa0
Patch
git.kernel.org / stable/c/25998f5613159fe35920dbd484fcac7ea3ad0799
Patch
git.kernel.org / stable/c/29b83a64df3b42c88c0338696feb6fdcd7f1f3b7
Patch
git.kernel.org / stable/c/38d647d509543e9434b3cc470b914348be271fe9
Patch
git.kernel.org / stable/c/64845ac64819683ad5e51b668b2ed56ee3386aee
Patch
git.kernel.org / stable/c/6bff05aaa32c2f7e1f6e68e890876642159db419
Patch
git.kernel.org / stable/c/6c1b9fe148a4e03bbfa234267ebb89f35285814a
Patch
git.kernel.org / stable/c/d996deb80398a90dd3c03590e68dad543da87d62
Patch
lists.debian.org / debian-lts-announce/2025/01/msg00001.html