CVE-2024-41007General(linux / linux_kernel)

LOWCVSS 3.3 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: tcp: avoid too many retransmit packets If a TCP socket is using TCP_USER_TIMEOUT, and the other peer retracted its window to zero, tcp_retransmit_timer() can retransmit a packet every two jiffies (2 ms for HZ=1000), for about 4 minutes after TCP_USER_TIMEOUT has 'expired'. The fix is to make sure tcp_rtx_probe0_timed_out() takes icsk->icsk_user_timeout into account. Before blamed commit, the socket would not timeout after icsk->icsk_user_timeout, but would use standard exponential backoff for the retransmits. Also worth noting that before commit e89688e3e978 ("net: tcp: fix unexcepted socket die when snd_wnd is 0"), the issue would last 2 minutes instead of 4.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-02-18); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
linux_kernel

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-02-18: 1Mentions · 2026-03-10: 1Mentions · 2026-03-25: 1Mentions · 2026-04-24: 1Mentions · 2026-06-07: 1Patch / Workaround · 2026-02-18: 1Technical Details · 2026-02-18: 102-1803-1003-2504-2406-07
Signal classification3 categories
General
360.0%
Patch
120.0%
Disclosure
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-181
Patch1
2026-03-101
General1
2026-03-251
General1
2026-04-241
General1
2026-06-071
Disclosure1
Full discourse5 posts
  • Ciberseguridad Hoy@ciberseghoy
    General

    Vulnerabilidad en kernel de Linux (CVE-2024-41007) https://ciberseguridadhoy.es/vulnerabilidad-en-kernel-de-linux-cve-2024-41007/?utm_source=ReviveOldPost&utm_medium=social&utm_campaign=ReviveOldPost

    Post summary

    The text only references a Linux kernel CVE with a link to an article, providing no further technical, exploitation, or mitigation details.

    0001048
    236 followersView on X
  • Ciberseguridad Hoy@ciberseghoy
    Disclosure

    Vulnerabilidad en kernel de Linux (CVE-2024-41007) https://ciberseguridadhoy.es/vulnerabilidad-en-kernel-de-linux-cve-2024-41007/?utm_source=ReviveOldPost&utm_medium=social&utm_campaign=ReviveOldPost

    Post summary

    The text announces the existence of a Linux kernel vulnerability (CVE‑2024‑41007) but provides no additional technical or operational details.

    0000026
    238 followersView on X
  • Ciberseguridad Hoy@ciberseghoy
    General

    Vulnerabilidad en kernel de Linux (CVE-2024-41007) https://ciberseguridadhoy.es/vulnerabilidad-en-kernel-de-linux-cve-2024-41007/?utm_source=ReviveOldPost&utm_medium=social&utm_campaign=ReviveOldPost

    Post summary

    The text references a Linux kernel vulnerability (CVE-2024-41007) but offers no further details, making it impossible to classify beyond a general mention.

    0000037
    239 followersView on X
  • Ciberseguridad Hoy@ciberseghoy
    General

    Vulnerabilidad en kernel de Linux (CVE-2024-41007) https://ciberseguridadhoy.es/vulnerabilidad-en-kernel-de-linux-cve-2024-41007/?utm_source=ReviveOldPost&utm_medium=social&utm_campaign=ReviveOldPost

    Post summary

    The passage announces a Linux kernel vulnerability (CVE-2024-41007) and links to an external article, but provides no additional details regarding PoC, exploitation tools, active attacks, patches, or technical specifics.

    0000050
    236 followersView on X
  • ThreatCluster@threatcluster
    Patch

    Microsoft publishes details on CVE-2025-38264 and CVE-2024-41007, critical flaws in TCP and NVMe over TCP that may impact systems using these protocols. Review and apply mitigations. #CVE https://threatcluster.io/cluster/cve-2025-38264-and-cve-2024-41007-published-by-microsoft-9d2bb47a

    Post summary

    Microsoft disclosed CVE‑2025‑38264 and CVE‑2024‑41007 as critical TCP and NVMe over TCP flaws, advising users to review and apply available mitigations.

    0000057
    71 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---

Explore more