Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-41003

20
FAUCET Score

CVE-2024-41003 is a vulnerability in the Linux kernel's BPF verifier, specifically affecting the reg_set_min_max function. It involves a register invariant violation that occurs when the verifier incorrectly handles "fake" registers during branch analysis, leading to a corruption of the fake_reg state. This flaw impacts the Linux kernel. The vulnerability is rated as HIGH severity with a CVSS score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating that a local attacker with low privileges can exploit it without user interaction. Successful exploitation could lead to high impacts on confidentiality, integrity, and availability, likely due to potential privilege escalation or denial of service. The underlying issue is categorized as CWE-787 (Out-of-bounds Write). Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has not been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, and there is minimal community discussion or media coverage surrounding it.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.8, < 6.9.7CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
6.10CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.10:rc1:*:*:*:*:*:*
6.10CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.10:rc2:*:*:*:*:*:*
6.10CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.10:rc3:*:*:*:*:*:*
6.10CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.10:rc4:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.28%
Probability of exploitation in next 30 days
EPSS Percentile
20.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0028 is in the 56th percentile among its peer group of 17,070 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2024-41003Low

kernel: bpf: Fix reg_set_min_max corruption of fake_reg

Jul 12, 2024

References

git.kernel.org / stable/c/41e8ab428a9964df378fa45760a660208712145b
Patch
git.kernel.org / stable/c/92424801261d1564a0bb759da3cf3ccd69fdf5a2
Patch