Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-40971

16
FAUCET Score

CVE-2024-40971 is a vulnerability in the Linux kernel's f2fs filesystem. During a remount operation, the SB_INLINECRYPT flag is temporarily cleared, creating a window where newly created or opened files might not use inline encryption, potentially leading to data corruption if wrappedkey_v0 is enabled. This vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring low privileges, and resulting in high impact to availability (data corruption). There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.8, < 5.10.221CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.162CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.96CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.36CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.7, < 6.9.7CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 79th percentile among its peer group of 15,940 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2024-40971Low

kernel: f2fs: remove clear SB_INLINECRYPT flag in default_options

Jul 12, 2024

References

cert-portal.siemens.com / productcert/html/ssa-265688.html
cert-portal.siemens.com / productcert/html/ssa-355557.html
git.kernel.org / stable/c/38a82c8d00638bb642bef787eb1d5e0e4d3b7d71
Patch
git.kernel.org / stable/c/724429db09e21ee153fef35e34342279d33df6ae
Patch
git.kernel.org / stable/c/a9cea0489c562c97cd56bb345e78939f9909e7f4
Patch
git.kernel.org / stable/c/ac5eecf481c29942eb9a862e758c0c8b68090c33
Patch
git.kernel.org / stable/c/ae39c8ec4250d2a35ddaab1c40faacfec306ff66
Patch
git.kernel.org / stable/c/eddeb8d941d5be11a9da5637dbe81ac37e8449a2
Patch
lists.debian.org / debian-lts-announce/2025/01/msg00001.html