Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-41007

15
FAUCET Score

CVE-2024-41007 is a vulnerability in the Linux kernel's TCP implementation where a socket configured with TCP_USER_TIMEOUT can excessively retransmit packets (every 2ms) for an extended period (up to 4 minutes) if the peer's window is zero, even after the user timeout has expired. This issue is rated as LOW severity (CVSS 3.1: 3.3/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L), indicating a local attack vector with low complexity and a potential impact of low availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.19, < 5.4.280CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.222CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.163CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.100CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.41CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.3LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
1.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
13.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0023 is in the 56th percentile among its peer group of 1,511 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (17)

autodeskpatch availablevia llm_extracted
View patch
freepbxpatch availablevia llm_extracted
View patch
honeywellpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.35.1-5 on Azure Linux 3.0Fixed in: 6.6.43.1-7
microsoftpatch availablevia msrc
Product: 17661-17084Fixed in: 6.6.43.1-7
microsoftpatch availablevia msrc
Product: 17671-17084Fixed in: 6.6.43.1-7
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.164.1-1 on CBL Mariner 2.0Fixed in: 5.15.164.1-1
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.162.2-1 on CBL Mariner 2.0Fixed in: 5.15.164.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.43.1-7 on Azure Linux 3.0Fixed in: 6.6.43.1-7
microsoftpatch availablevia msrc
Product: 17250-16823Fixed in: 5.15.164.1-1
microsoftpatch availablevia msrc
Product: 19731-17086Fixed in: 5.15.164.1-1
microsoftpatch availablevia msrc
Product: 17233-17086Fixed in: 5.15.164.1-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-553.22.1.rt7.363.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: kernel-0:5.14.0-427.47.1.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-503.11.1.el9_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.22.1.el8_10
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (5)

honeywellllm-honeywell-c82b5cfda9df97a3CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
autodeskllm-autodesk-c365b674a2ff5a3aCRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
freepbxllm-freepbx-e54908c7967265f6CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
redhatCVE-2024-41007Moderate

kernel: tcp: avoid too many retransmit packets

Jul 15, 2024
microsoft2024-Jul/CVE-2024-41007Low

tcp: avoid too many retransmit packets

Jul 9, 2024

References

git.kernel.org / stable/c/04317a2471c2f637b4c49cbd0e9c0d04a519f570
Patch
git.kernel.org / stable/c/5d7e64d70a11d988553a08239c810a658e841982
Patch
git.kernel.org / stable/c/66cb64a1d2239cd0309f9b5038b05462570a5be1
Patch
git.kernel.org / stable/c/7bb7670f92bfbd05fc41a8f9a8f358b7ffed65f4
Patch
git.kernel.org / stable/c/97a9063518f198ec0adb2ecb89789de342bb8283
Patch
git.kernel.org / stable/c/d2346fca5bed130dc712f276ac63450201d52969
Patch
git.kernel.org / stable/c/dfcdd7f89e401d2c6616be90c76c2fac3fa98fde
Patch
git.kernel.org / stable/c/e113cddefa27bbf5a79f72387b8fbd432a61a466
Patch
lists.debian.org / debian-lts-announce/2025/01/msg00001.html