Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-41006

17
FAUCET Score

CVE-2024-41006 describes a memory leak in the Linux kernel's NetROM (nr_heartbeat_expiry) module. Specifically, a reference count was unnecessarily incremented for sockets marked for destruction, preventing proper memory deallocation. This vulnerability affects the Linux kernel. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring local privileges. The primary impact is a denial of service due to resource exhaustion (CWE-401). There is currently no evidence of active exploitation, nor are there public exploit codes available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.19.272, < 4.19.317CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.4.231, < 5.4.279CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.10.166, < 5.10.221CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.15.91, < 5.15.162CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.1.9, < 6.1.96CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 67th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

microsoftpatch availablevia msrc
Product: 17651-17084Fixed in: 6.6.47.1-1
microsoftpatch availablevia msrc
Product: 17671-17084Fixed in: 6.6.47.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.47.1-1 on Azure Linux 3.0Fixed in: 6.6.47.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.35.1-5 on Azure Linux 3.0Fixed in: 6.6.47.1-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 6.6.47.1-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 6.6.47.1-1

Vendor Advisories (3)

microsoft2024-Sep/CVE-2024-41006

CVE-2024-41006

Sep 10, 2024
redhatCVE-2024-41006Low

kernel: netrom: Fix a memory leak in nr_heartbeat_expiry()

Jul 12, 2024
microsoft2024-Jul/CVE-2024-41006Moderate

netrom: Fix a memory leak in nr_heartbeat_expiry()

Jul 9, 2024

References

cert-portal.siemens.com / productcert/html/ssa-265688.html
cert-portal.siemens.com / productcert/html/ssa-355557.html
cert-portal.siemens.com / productcert/html/ssa-613116.html
git.kernel.org / stable/c/0b9130247f3b6a1122478471ff0e014ea96bb735
Mailing ListPatch
git.kernel.org / stable/c/280cf1173726a7059b628c610c71050d5c0b6937
Mailing ListPatch
git.kernel.org / stable/c/5391f9db2cab5ef1cb411be1ab7dbec728078fba
Mailing ListPatch
git.kernel.org / stable/c/a02fd5d775cf9787ee7698c797e20f2fa13d2e2b
Mailing ListPatch
git.kernel.org / stable/c/b6ebe4fed73eedeb73f4540f8edc4871945474c8
Mailing ListPatch
git.kernel.org / stable/c/d377f5a28332954b19e373d36823e59830ab1712
Mailing ListPatch
git.kernel.org / stable/c/d616876256b38ecf9a1a1c7d674192c5346bc69c
Mailing ListPatch
git.kernel.org / stable/c/e07a9c2a850cdebf625e7a1b8171bd23a8554313
Mailing ListPatch
lists.debian.org / debian-lts-announce/2025/01/msg00001.html