In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix access violation during port device removal Testing with KASAN and syzkaller revealed a bug in port.c:disable_store(): usb_hub_to_struct_hub() can return NULL if the hub that the port belongs to is concurrently removed, but the function does not check for this possibility before dereferencing the returned value. It turns out that the first dereference is unnecessary, since hub->intfdev is the parent of the port device, so it can be changed easily. Adding a check for hub == NULL prevents further problems. The same bug exists in the disable_show() routine, and it can be fixed the same way.
Conclusion & alert: CVE-2024-36896 is rated Moderate Risk (43.4/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.07%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 0.89% | 0.07% | -0.82% |
| 2 | 2025-11-18 | 0.07% | 0.89% | +0.82% |
| 3 | 2025-07-08 | — | 0.07% | — |
Full EPSS history (10 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.1 | 3.1 | CRITICAL |
|
3.9 | 5.2 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2024-36896 unimportant priority: Debian including 1 source packages (linux), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2024-36896 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2024-36896 |
suse
|
medium | — | https://www.suse.com/security/cve/CVE-2024-36896/ |
ubuntu
|
medium | CVE-2024-36896 medium priority: Ubuntu including 128 source packages (linux, linux-allwinner-5.19, …), 1139 status rows across 9 suites (bionic, focal, jammy, mantic, noble, oracular, trusty, upstream, xenial): DNE 808, ignored 144, released 95, not-affected 92. | https://ubuntu.com/security/CVE-2024-36896 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| linux | linux_kernel | >= 6.0, < 6.1.91 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | >= 6.2, < 6.6.31 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | >= 6.7, < 6.8.10 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | 6.9 | cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:* |
| linux | linux_kernel | 6.9 | cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:* |
| linux | linux_kernel | 6.9 | cpe:2.3:o:linux:linux_kernel:6.9:rc3:*:*:*:*:*:* |
| linux | linux_kernel | 6.9 | cpe:2.3:o:linux:linux_kernel:6.9:rc4:*:*:*:*:*:* |
| linux | linux_kernel | 6.9 | cpe:2.3:o:linux:linux_kernel:6.9:rc5:*:*:*:*:*:* |
| linux | linux_kernel | 6.9 | cpe:2.3:o:linux:linux_kernel:6.9:rc6:*:*:*:*:*:* |