Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-50171

18
FAUCET Score

CVE-2024-50171 is a memory leak vulnerability in the Linux kernel's net: systemport component, specifically within the bcm_sysport_xmit() function. This flaw occurs when dma_map_single() fails, leading to an un-freed skb. With a CVSS score of 5.5 (Medium), it can be exploited locally with low complexity, resulting in high availability impact. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.16CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.19, < 4.19.323CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.285CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.229CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.170CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 65th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (14)

autodeskpatch availablevia llm_extracted
View patch
freepbxpatch availablevia llm_extracted
View patch
honeywellpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: 19672-17086Fixed in: 5.15.173.1-1
microsoftpatch availablevia msrc
Product: 17156-17086Fixed in: 5.15.173.1-1
microsoftpatch availablevia msrc
Product: 17489-17084Fixed in: 6.6.64.2-1
microsoftpatch availablevia msrc
Product: 17088-17084Fixed in: 6.6.64.2-1
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.173.1-1 on CBL Mariner 2.0Fixed in: 5.15.173.1-1
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.167.1-2 on CBL Mariner 2.0Fixed in: 5.15.173.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.64.2-1 on Azure Linux 3.0Fixed in: 6.6.64.2-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 5.15.173.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.57.1-7 on Azure Linux 3.0Fixed in: 6.6.64.2-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 5.15.173.1-1
microsoftpatch availablevia msrc
Product: 17123-16823Fixed in: 5.15.173.1-1

Vendor Advisories (6)

honeywellllm-honeywell-c82b5cfda9df97a3CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
autodeskllm-autodesk-c365b674a2ff5a3aCRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
freepbxllm-freepbx-e54908c7967265f6CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
microsoft2024-Dec/CVE-2024-50171

CVE-2024-50171

Dec 10, 2024
microsoft2024-Nov/CVE-2024-50171Moderate

net: systemport: fix potential memory leak in bcm_sysport_xmit()

Nov 12, 2024
redhatCVE-2024-50171Moderate

kernel: net: systemport: fix potential memory leak in bcm_sysport_xmit()

Nov 7, 2024

References

git.kernel.org / stable/c/31701ef0c4547973991ff63596c927f841dfd133
Patch
git.kernel.org / stable/c/4b70478b984af3c9d0279c121df5ff94e2533dbd
Patch
git.kernel.org / stable/c/533d2f30aef272dade17870a509521c3afc38a03
Patch
git.kernel.org / stable/c/5febfc545389805ce83d37f9f4317055b26dd7d7
Patch
git.kernel.org / stable/c/7d5030a819c3589cf9948b1eee397b626ec590f5
Patch
git.kernel.org / stable/c/8e81ce7d0166a2249deb6d5e42f28a8b8c9ea72f
Patch
git.kernel.org / stable/c/b6321146773dcbbc372a54dbada67e0b50e0a25c
Patch
git.kernel.org / stable/c/c401ed1c709948e57945485088413e1bb5e94bd1
Patch
lists.debian.org / debian-lts-announce/2025/01/msg00001.html
lists.debian.org / debian-lts-announce/2025/03/msg00002.html