Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-40974

21
FAUCET Score

CVE-2024-40974 is a Linux kernel vulnerability affecting powerpc/pseries that stems from insufficient validation of result buffer sizes in plpar_hcall() and related functions. This can lead to stack corruption if a caller provides an undersized buffer, allowing an attacker with local privileges to potentially achieve high impact on confidentiality, integrity, and availability. While the vulnerability has a CVSS score of 7.8 (High), there is currently no evidence of active exploitation, public exploit code, or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.19.317CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.279CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.221CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.162CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.96CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 59th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.16.1.el8_10
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2024-40974Moderate

kernel: powerpc/pseries: Enforce hcall result buffer validity and size

Jul 12, 2024

References

git.kernel.org / stable/c/19c166ee42cf16d8b156a6cb4544122d9a65d3ca
Patch
git.kernel.org / stable/c/262e942ff5a839b9e4f3302a8987928b0c8b8a2d
Patch
git.kernel.org / stable/c/3ad0034910a57aa88ed9976b1431b7b8c84e0048
Patch
git.kernel.org / stable/c/8aa11aa001576bf3b00dcb8559564ad7a3113588
Patch
git.kernel.org / stable/c/a8c988d752b3d98d5cc1e3929c519a55ef55426c
Patch
git.kernel.org / stable/c/aa6107dcc4ce9a3451f2d729204713783b657257
Patch
git.kernel.org / stable/c/acf2b80c31c37acab040baa3cf5f19fbd5140b18
Patch
git.kernel.org / stable/c/ff2e185cf73df480ec69675936c4ee75a445c3e4
Patch
lists.debian.org / debian-lts-announce/2025/01/msg00001.html