Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-53157

18
FAUCET Score

CVE-2024-53157 is a Linux kernel vulnerability affecting the arm_scpi firmware component. It causes a kernel crash (NULL pointer dereference) when the SCPI firmware returns a zero DVFS OPP count, particularly during reboot tests on some platforms. This vulnerability has a CVSS score of 5.5 (MEDIUM), indicating a local attack vector with low complexity, requiring local privileges, and resulting in high availability impact (system crash). There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.4, < 4.19.325CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.287CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.231CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.174CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.120CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
13.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0023 is in the 61st percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

autodeskpatch availablevia llm_extracted
View patch
freepbxpatch availablevia llm_extracted
View patch
honeywellpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: 17489-17084Fixed in: 6.6.64.2-1
microsoftpatch availablevia msrc
Product: 17088-17084Fixed in: 6.6.64.2-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.57.1-7 on Azure Linux 3.0Fixed in: 6.6.64.2-1
microsoftpatch availablevia msrc
Product: 17110-16823Fixed in: 5.15.176.3-1
microsoftpatch availablevia msrc
Product: 19675-17086Fixed in: 5.15.176.3-1
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.173.1-2 on CBL Mariner 2.0Fixed in: 5.15.176.3-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.64.2-1 on Azure Linux 3.0Fixed in: 6.6.64.2-1
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.176.3-1 on CBL Mariner 2.0Fixed in: 5.15.176.3-1
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel

Vendor Advisories (5)

honeywellllm-honeywell-c82b5cfda9df97a3CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
autodeskllm-autodesk-c365b674a2ff5a3aCRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
freepbxllm-freepbx-e54908c7967265f6CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
redhatCVE-2024-53157Low

kernel: firmware: arm_scpi: Check the DVFS OPP count returned by the firmware

Dec 24, 2024
microsoft2024-Dec/CVE-2024-53157Moderate

firmware: arm_scpi: Check the DVFS OPP count returned by the firmware

Dec 10, 2024

References

git.kernel.org / stable/c/025067eeb945aa17c7dd483a63960125b7efb577
Patch
git.kernel.org / stable/c/06258e57fee253f4046d3a6a86d7fde09f596eac
Patch
git.kernel.org / stable/c/109aa654f85c5141e813b2cd1bd36d90be678407
Patch
git.kernel.org / stable/c/12e2c520a0a4202575e4a45ea41f06a8e9aa3417
Patch
git.kernel.org / stable/c/2a5b8de6fcb944f9af0c5fcb30bb0c039705e051
Patch
git.kernel.org / stable/c/380c0e1d96f3b522f3170c18ee5e0f1a28fec5d6
Patch
git.kernel.org / stable/c/8be4e51f3ecfb0915e3510b600c4cce0dc68a383
Patch
git.kernel.org / stable/c/9beaff47bcea5eec7d4ead98f5043057161fd71a
Patch
git.kernel.org / stable/c/dfc9c2aa7f04f7db7e7225a5e118a24bf1c3b325
Patch
lists.debian.org / debian-lts-announce/2025/03/msg00001.html
lists.debian.org / debian-lts-announce/2025/03/msg00002.html