Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-40993

17
FAUCET Score

CVE-2024-40993 is a medium-severity vulnerability in the Linux kernel's netfilter ipset component, specifically related to improper handling during set destruction. This flaw could lead to a denial-of-service (DoS) condition (high availability impact) due to a suspicious rcu_dereference_protected() call. The attack requires local access and low privileges, with low attack complexity. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
6.1.95CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.1.95:*:*:*:*:*:*:*
6.6.35CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.6.35:*:*:*:*:*:*:*
6.9.6CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.9.6:*:*:*:*:*:*:*
6.10CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.10:rc4:*:*:*:*:*:*
>= 6.1.95, < 6.1.96CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.28%
Probability of exploitation in next 30 days
EPSS Percentile
20.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0028 is in the 76th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2024-40993Moderate

kernel: netfilter: ipset: Fix suspicious rcu_dereference_protected()

Jul 12, 2024

References

cert-portal.siemens.com / productcert/html/ssa-265688.html
git.kernel.org / stable/c/3799d02ae4208af08e81310770d8754863a246a1
Patch
git.kernel.org / stable/c/3fc09e1ca854bc234e007a56e0f7431f5e2defb5
Patch
git.kernel.org / stable/c/523bed6489e089dd8040e72453fb79da47b144c2
Patch
git.kernel.org / stable/c/72d9611968867cc4c5509e7708b1507d692b797a
Patch
git.kernel.org / stable/c/788d585e62f487bc4536d454937f737b70d39a33
Patch
git.kernel.org / stable/c/8ecd06277a7664f4ef018abae3abd3451d64e7a6
Patch
git.kernel.org / stable/c/94dd411c18d7fff9e411555d5c662d29416501e4
Patch
lists.debian.org / debian-lts-announce/2025/01/msg00001.html