LiveActive security incident?Get immediate response
CVE Record

CVE-2024-38615: cpufreq: exit() callback is optional

In the Linux kernel, the following vulnerability has been resolved: cpufreq: exit() callback is optional The exit() callback is optional and shouldn't be called without checking a valid pointer first. Also, we must clear freq_table pointer even if the exit() callback isn't present.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2024-38615 is a Linux kernel cpufreq bug where the kernel could call an optional driver cleanup callback without first confirming it exists. The public record does not provide CVSS, CWE, or concrete impact details, so business urgency should be based on exposed Linux versions and vendor advisories.

Executive priority

Treat this as a routine-to-watch kernel maintenance item unless vendor guidance shows your products are affected or critical. There is no sourced evidence of active exploitation or a severity score in the supplied bundle.

Technical view

The resolved kernel change makes cpufreq treat the exit() callback as optional and clears the freq_table pointer even when no exit() callback is present. The source bundle indicates Linux kernel impact and references stable kernel commits, but does not describe exploitability, attacker prerequisites, or security impact class.

Likely exposure

Exposure is likely limited to systems running affected Linux kernel versions or vendor products that include those kernels. Siemens advisories are referenced, but this bundle does not name specific Siemens product impact details.

Exploitation context

No active exploitation is supported by the supplied sources. KEV is false, and the bundle provides no exploit reports, proof-of-concept references, or weaponized attack details.

Researcher notes

The key technical signal is defensive handling of an optional cpufreq driver exit() callback and freq_table cleanup. The record lacks enough detail to rate impact confidently; validation should focus on kernel lineage, downstream vendor advisories, and whether affected cpufreq paths exist in deployed builds.

Mitigation direction

  • Check Linux distribution advisories for CVE-2024-38615 fixed kernel packages.
  • Review Siemens SSA-265688 and SSA-613116 if Siemens products are in scope.
  • Prioritize kernel updates on systems using CPU frequency scaling features.
  • Track stable kernel commits referenced in the CVE record.
  • Avoid assuming mitigation beyond vendor-published kernel updates.

Validation and detection

  • Inventory Linux kernel versions across servers, appliances, and embedded systems.
  • Compare deployed kernels against vendor advisories and fixed stable branches.
  • Identify Siemens assets covered by SSA-265688 or SSA-613116.
  • Confirm update status through package manager or firmware inventory records.
  • Document any unsupported kernels requiring compensating risk acceptance.
Prepared
Confidence
medium
Sources
12

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2024-38615 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
3ADP providers
11Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
siemens-SADPADP container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux91a12e91dc39137906d929a4ff6f9c32c59697fa, 91a12e91dc39137906d929a4ff6f9c32c59697fa, 91a12e91dc39137906d929a4ff6f9c32c59697fa, 91a12e91dc39137906d929a4ff6f9c32c59697fa, 91a12e91dc39137906d929a4ff6f9c32c59697fa, 91a12e91dc39137906d929a4ff6f9c32c59697fa, 91a12e91dc39137906d929a4ff6f9c32c59697fa, 91a12e91dc39137906d929a4ff6f9c32c59697faunaffected
LinuxLinux5.1, 0, 5.4.278, 5.10.219, 5.15.161, 6.1.93, 6.6.33, 6.8.12, 6.9.3, 6.10affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.