Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-56533

17
FAUCET Score

CVE-2024-56533 addresses a vulnerability in the Linux kernel's ALSA USB audio driver (usx2y) where the snd_card_free() function was used during USB device disconnection. This could lead to a soft lockup by blocking upper-layer USB ioctls due to prolonged waiting for file descriptor closure. The vulnerability is rated Medium (CVSS 5.5) with a low attack complexity and requires local privileges, potentially leading to high availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.13, < 5.10.231CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.174CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.120CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.64CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.7, < 6.11.11CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
11.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0021 is in the 52nd percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

autodeskpatch availablevia llm_extracted
View patch
freepbxpatch availablevia llm_extracted
View patch
honeywellpatch availablevia llm_extracted
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (4)

honeywellllm-honeywell-c82b5cfda9df97a3CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
autodeskllm-autodesk-c365b674a2ff5a3aCRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
freepbxllm-freepbx-e54908c7967265f6CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
redhatCVE-2024-56533Low

kernel: ALSA: usx2y: Use snd_card_free_when_closed() at disconnection

Dec 27, 2024

References

git.kernel.org / stable/c/24fe9f7ca83ec9acf765339054951f5cd9ae5c5d
Patch
git.kernel.org / stable/c/7bd8838c0ea886679a32834fdcacab296d072fbe
Patch
git.kernel.org / stable/c/befcca1777525e37c659b4129d8ac7463b07ef67
Patch
git.kernel.org / stable/c/dafb28f02be407e07a6f679e922a626592b481b0
Patch
git.kernel.org / stable/c/e07605d855c4104d981653146a330ea48f6266ed
Patch
git.kernel.org / stable/c/e869642a77a9b3b98b0ab2c8fec7af4385140909
Patch
git.kernel.org / stable/c/ffbfc6c4330fc233698529656798bee44fea96f5
Patch
lists.debian.org / debian-lts-announce/2025/03/msg00001.html
lists.debian.org / debian-lts-announce/2025/03/msg00002.html