Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-4741

24
FAUCET Score

CVE-2024-4741 is a use-after-free vulnerability in OpenSSL's SSL_free_buffers function, affecting applications that directly call this rarely used API. The vulnerability occurs when SSL_free_buffers is called while an internal buffer is still in use, either due to a partially processed record or an incompletely read record. With a CVSS score of 7.5 (High), it could lead to data corruption, crashes, or arbitrary code execution, though only applications explicitly using SSL_free_buffers are vulnerable. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.1.1, < 1.1.1yCPE match
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.0.0, < 3.0.14CPE match
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.1.0, < 3.1.6CPE match
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.2.0, < 3.2.2CPE match
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.3.0, < 3.3.1CPE match
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.94%
Probability of exploitation in next 30 days
EPSS Percentile
85.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0295 is in the 74th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (33)

jitsipatch availablevia llm_extracted
Fixed in: 3.3.1
View patch
microsoftpatch availablevia msrc
Product: 17238-17086Fixed in: 1.0.1-6
microsoftpatch availablevia msrc
Product: 17290-16823Fixed in: 1.1.1k-31
microsoftpatch availablevia msrc
Product: 19813-17086Fixed in: 1.1.1k-31
microsoftpatch availablevia msrc
Product: 17488-17084Fixed in: 20240524git3e722403cd16-6
microsoftpatch availablevia msrc
Product: 17627-17084Fixed in: 20240524git3e722403cd16-6
microsoftpatch availablevia msrc
Product: 19809-17086Fixed in: 1.0.1-6
microsoftpatch availablevia msrc
Product: 17178-16823Fixed in: 1.0.1-6
microsoftpatch availablevia msrc
Product: cbl2 hvloader 1.0.1-6 on CBL Mariner 2.0Fixed in: 1.0.1-6
microsoftpatch availablevia msrc
Product: cbl2 hvloader 1.0.1-5 on CBL Mariner 2.0Fixed in: 1.0.1-6
microsoftpatch availablevia msrc
Product: cbl2 openssl 1.1.1k-31 on CBL Mariner 2.0Fixed in: 1.1.1k-31
microsoftpatch availablevia msrc
Product: cbl2 openssl 1.1.1k-36 on CBL Mariner 2.0Fixed in: 1.1.1k-31
microsoftpatch availablevia msrc
Product: azl3 edk2 20240524git3e722403cd16-6 on Azure Linux 3.0Fixed in: 20240524git3e722403cd16-6
microsoftpatch availablevia msrc
Product: azl3 edk2 20240524git3e722403cd16-8 on Azure Linux 3.0Fixed in: 20240524git3e722403cd16-6
nodejspatch availablevia llm_extracted
View patch
pjsippatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: openssl-1:3.2.2-6.el9_5
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Core ServicesFixed in: openssl
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Web Server 5Fixed in: openssl
redhatvendor investigatingvia redhat_api
Product: Red Hat Satellite 6Fixed in: python3.12-pyOpenSSL
redhatvendor investigatingvia redhat_api
Product: Red Hat Satellite 6Fixed in: python-pyOpenSSL
redhatvendor investigatingvia redhat_api
Product: Red Hat Satellite 6Fixed in: satellite-capsule:el8/python-pyOpenSSL
redhatvendor investigatingvia redhat_api
Product: Red Hat Satellite 6Fixed in: satellite:el8/python-pyOpenSSL
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: edk2
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: compat-openssl11
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: edk2
redhatvendor investigatingvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp-backend-container
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: ovmf
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: mingw-openssl
redhatvendor investigatingvia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/fluentd-rhel9
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: openssl
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: openssl
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: openssl

Vendor Advisories (5)

microsoft2024-Nov/CVE-2024-4741Important

Use After Free with SSL_free_buffers

Nov 12, 2024
nodejsllm-nodejs-302528ae26f0d946CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
pjsipllm-pjsip-7ba3ec379210ac70CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
redhatCVE-2024-4741Low

openssl: Use After Free with SSL_free_buffers

May 28, 2024
jitsillm-jitsi-0337f03496fc16d1LOW

Use After Free with SSL_free_buffers

May 27, 2024

References

lists.debian.org / debian-lts-announce/2024/10/msg00033.html
lists.debian.org / debian-lts-announce/2024/11/msg00000.html
security.netapp.com / advisory/ntap-20240621-0004
github.com / openssl/openssl/commit/704f725b96aa373ee45ecfb23f6abfe8be8d9177
github.com / openssl/openssl/commit/b3f0eb0a295f58f16ba43ba99dad70d4ee5c437d
github.com / openssl/openssl/commit/c88c3de51020c37e8706bf7a682a162593053aac
github.com / openssl/openssl/commit/e5093133c35ca82874ad83697af76f4b0f7e3bd8
github.openssl.org / openssl/extended-releases/commit/f7a045f3143fc6da2ee66bf52d8df04829590dd4
openssl.org / news/secadv/20240528.txt