Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-43845

13
FAUCET Score

CVE-2024-43845 describes an uninitialized memory access vulnerability in the Linux kernel's UDF filesystem, specifically within the udf_rename() function. This flaw, identified by Syzbot, occurs during the checksum computation of a moved directory's ".." entry, where random stack contents are incorrectly included. While the subsequent udf_fiiter_write_fi() function corrects the checksum, the initial computation is erroneous. The vulnerability has a CVSS score of 3.3 (Low severity), indicating a local attack vector with low attack complexity, requiring low privileges, and resulting in a low impact on integrity (CWE-908). There is no impact on confidentiality or availability. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public attention.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.3, < 6.6.44CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.7, < 6.10.3CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.3LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
11.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0021 is in the 51st percentile among its peer group of 1,511 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

codesyspatch availablevia llm_extracted
View patch
esphomepatch availablevia llm_extracted
View patch

Vendor Advisories (3)

codesysllm-codesys-fe85e88fbae25bb9CRITICAL

HP ThinPro 8.1 SP7 Security Updates

Jun 3, 2025
esphomellm-esphome-ed450ce9fd6a7380CRITICAL

HP ThinPro 8.1 SP7 Security Updates

Jun 3, 2025
redhatCVE-2024-43845Low

kernel: udf: Fix bogus checksum computation in udf_rename()

Aug 17, 2024

References

git.kernel.org / stable/c/27ab33854873e6fb958cb074681a0107cc2ecc4c
Patch
git.kernel.org / stable/c/40d7b3ed52449d36143bab8d3e70926aa61a60f4
Patch
git.kernel.org / stable/c/9c439311c13fc6faab1921441165c9b8b500c83b
Patch
git.kernel.org / stable/c/fe2ead240c31e8d158713beca9d0681a6e6a53ab
Patch