Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-57951

21
FAUCET Score

CVE-2024-57951 is a Linux kernel vulnerability related to incorrect handling of CPU state during hotplug operations, specifically affecting hrtimers. This flaw can lead to an inconsistent state where hrtimers are not properly re-initialized after a CPU hotunplug and subsequent hotplug, potentially causing system instability or incorrect behavior. Rated 7.8 HIGH (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), it requires local access and low privileges, but can result in high impact to confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.19.302, < 4.20CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.4.264, < 5.4.290CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.10.204, < 5.10.234CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.15.143, < 5.15.177CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.1.68, < 6.1.127CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
14.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0023 is in the 46th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (15)

autodeskpatch availablevia llm_extracted
View patch
freepbxpatch availablevia llm_extracted
View patch
honeywellpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: 17099-17086Fixed in: 5.15.180.1-1
microsoftpatch availablevia msrc
Product: 17476-17084Fixed in: 6.6.76.1-1
microsoftpatch availablevia msrc
Product: 17501-17084Fixed in: 6.6.76.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.64.2-9 on Azure Linux 3.0Fixed in: 6.6.76.1-1
microsoftpatch availablevia msrc
Product: 17095-16823Fixed in: 5.15.180.1-1
microsoftpatch availablevia msrc
Product: 19705-17086Fixed in: 5.15.180.1-1
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.180.1-1 on CBL Mariner 2.0Fixed in: 5.15.180.1-1
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.176.3-3 on CBL Mariner 2.0Fixed in: 5.15.180.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.76.1-1 on Azure Linux 3.0Fixed in: 6.6.76.1-1
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel

Vendor Advisories (5)

honeywellllm-honeywell-c82b5cfda9df97a3CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
autodeskllm-autodesk-c365b674a2ff5a3aCRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
freepbxllm-freepbx-e54908c7967265f6CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
redhatCVE-2024-57951Moderate

kernel: hrtimers: Handle CPU state correctly on hotplug

Feb 12, 2025
microsoft2025-Feb/CVE-2024-57951Important

hrtimers: Handle CPU state correctly on hotplug

Feb 11, 2025

References

cert-portal.siemens.com / productcert/html/ssa-265688.html
cert-portal.siemens.com / productcert/html/ssa-355557.html
git.kernel.org / stable/c/14984139f1f2768883332965db566ef26db609e7
Patch
git.kernel.org / stable/c/15b453db41d36184cf0ccc21e7df624014ab6a1a
Patch
git.kernel.org / stable/c/2f8dea1692eef2b7ba6a256246ed82c365fdc686
Patch
git.kernel.org / stable/c/38492f6ee883c7b1d33338bf531a62cff69b4b28
Patch
git.kernel.org / stable/c/3d41dbf82e10c44e53ea602398ab002baec27e75
Patch
git.kernel.org / stable/c/95e4f62df23f4df1ce6ef897d44b8e23c260921a
Patch
git.kernel.org / stable/c/a5cbbea145b400e40540c34816d16d36e0374fbc
Patch
lists.debian.org / debian-lts-announce/2025/03/msg00001.html
lists.debian.org / debian-lts-announce/2025/03/msg00002.html