Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-45016

18
FAUCET Score

CVE-2024-45016 is a use-after-free vulnerability in the Linux kernel's netem network emulator, specifically affecting the netem_enqueue() function. This flaw, introduced by a previous commit, can lead to incorrect qdisc queue length tracking, potentially leaving dangling pointers in classful qdiscs like DRR. The vulnerability has a CVSS v3.1 score of 5.5 (Medium), indicating a local attack vector with low attack complexity, requiring low privileges, and resulting in high availability impact (denial of service). There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, nor are there any public exploit modules available for Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.0, < 5.4.283CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.225CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.166CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.107CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.48CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 65th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (17)

microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.47.1-1 on Azure Linux 3.0Fixed in: 6.6.51.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 5.15.167.1-1
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.167.1-1 on CBL Mariner 2.0Fixed in: 5.15.167.1-1
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.164.1-1 on CBL Mariner 2.0Fixed in: 5.15.167.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.51.1-1 on Azure Linux 3.0Fixed in: 6.6.51.1-1
microsoftpatch availablevia msrc
Product: 17207-16823Fixed in: 5.15.167.1-1
microsoftpatch availablevia msrc
Product: 19670-17086Fixed in: 5.15.167.1-1
microsoftpatch availablevia msrc
Product: 17250-17086Fixed in: 5.15.167.1-1
microsoftpatch availablevia msrc
Product: 17631-17084Fixed in: 6.6.51.1-1
microsoftpatch availablevia msrc
Product: 17651-17084Fixed in: 6.6.51.1-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 6.6.51.1-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 6.6.51.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 5.15.167.1-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-570.12.1.el9_6
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt

Vendor Advisories (3)

microsoft2024-Oct/CVE-2024-45016

CVE-2024-45016

Oct 8, 2024
redhatCVE-2024-45016Moderate

kernel: netem: fix return value if duplicate enqueue fails

Sep 11, 2024
microsoft2024-Sep/CVE-2024-45016Moderate

netem: fix return value if duplicate enqueue fails

Sep 10, 2024

References

cert-portal.siemens.com / productcert/html/ssa-265688.html
git.kernel.org / stable/c/0486d31dd8198e22b63a4730244b38fffce6d469
Patch
git.kernel.org / stable/c/52d99a69f3d556c6426048c9d481b912205919d8
Patch
git.kernel.org / stable/c/577d6c0619467fe90f7e8e57e45cb5bd9d936014
Patch
git.kernel.org / stable/c/759e3e8c4a6a6b4e52ebc4547123a457f0ce90d4
Patch
git.kernel.org / stable/c/c07ff8592d57ed258afee5a5e04991a48dbaf382
Patch
git.kernel.org / stable/c/c414000da1c2ea1ba9a5e5bb1a4ba774e51e202d
Patch
git.kernel.org / stable/c/e5bb2988a310667abed66c7d3ffa28880cf0f883
Patch
lists.debian.org / debian-lts-announce/2024/10/msg00003.html
lists.debian.org / debian-lts-announce/2025/01/msg00001.html