Answer in brief
CVE-2024-41007 records a Unknown severity vulnerability in tcp: avoid too many retransmit packets. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2024-41007 records a Unknown severity vulnerability in tcp: avoid too many retransmit packets. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b701a99e431db784714c32fc6b68123045714679 <7bb7670f92bfbd05fc41a8f9a8f358b7ffed65f4 || >=b701a99e431db784714c32fc6b68123045714679 <d2346fca5bed130dc712f276ac63450201d52969 || >=b701a99e431db784714c32fc6b68123045714679 <5d7e64d70a11d988553a08239c810a658e841982 || >=b701a99e431db784714c32fc6b68123045714679 <04317a2471c2f637b4c49cbd0e9c0d04a519f570 || >=b701a99e431db784714c32fc6b68123045714679 <e113cddefa27bbf5a79f72387b8fbd432a61a466 || >=b701a99e431db784714c32fc6b68123045714679 <dfcdd7f89e401d2c6616be90c76c2fac3fa98fde || >=b701a99e431db784714c32fc6b68123045714679 <66cb64a1d2239cd0309f9b5038b05462570a5be1 || >=b701a99e431db784714c32fc6b68123045714679 <97a9063518f198ec0adb2ecb89789de342bb8283 | 7bb7670f92bfbd05fc41a8f9a8f358b7ffed65f4, d2346fca5bed130dc712f276ac63450201d52969, 5d7e64d70a11d988553a08239c810a658e841982, 04317a2471c2f637b4c49cbd0e9c0d04a519f570, e113cddefa27bbf5a79f72387b8fbd432a61a466, dfcdd7f89e401d2c6616be90c76c2fac3fa98fde, 66cb64a1d2239cd0309f9b5038b05462570a5be1, 97a9063518f198ec0adb2ecb89789de342bb8283 |
| Linux/Linuxgeneric | 4.19 | Not reported |
Published upstream
Jul 15, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: tcp: avoid too many retransmit packets If a TCP socket is using TCP_USER_TIMEOUT, and the other peer retracted its window to zero, tcp_retransmit_timer() can retransmit a packet every two jiffies (2 ms for HZ=1000), for about 4 minutes after TCP_USER_TIMEOUT has 'expired'. The fix is to make sure tcp_rtx_probe0_timed_out() takes icsk->icsk_user_timeout into account. Before blamed commit, the socket would not timeout after icsk->icsk_user_timeout, but would use standard exponential backoff for the retransmits. Also worth noting that before commit e89688e3e978 ("net: tcp: fix unexcepted socket die when snd_wnd is 0"), the issue would last 2 minutes instead of 4.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b701a99e431db784714c32fc6b68123045714679 <7bb7670f92bfbd05fc41a8f9a8f358b7ffed65f4 || >=b701a99e431db784714c32fc6b68123045714679 <d2346fca5bed130dc712f276ac63450201d52969 || >=b701a99e431db784714c32fc6b68123045714679 <5d7e64d70a11d988553a08239c810a658e841982 || >=b701a99e431db784714c32fc6b68123045714679 <04317a2471c2f637b4c49cbd0e9c0d04a519f570 || >=b701a99e431db784714c32fc6b68123045714679 <e113cddefa27bbf5a79f72387b8fbd432a61a466 || >=b701a99e431db784714c32fc6b68123045714679 <dfcdd7f89e401d2c6616be90c76c2fac3fa98fde || >=b701a99e431db784714c32fc6b68123045714679 <66cb64a1d2239cd0309f9b5038b05462570a5be1 || >=b701a99e431db784714c32fc6b68123045714679 <97a9063518f198ec0adb2ecb89789de342bb8283 | 7bb7670f92bfbd05fc41a8f9a8f358b7ffed65f4, d2346fca5bed130dc712f276ac63450201d52969, 5d7e64d70a11d988553a08239c810a658e841982, 04317a2471c2f637b4c49cbd0e9c0d04a519f570, e113cddefa27bbf5a79f72387b8fbd432a61a466, dfcdd7f89e401d2c6616be90c76c2fac3fa98fde, 66cb64a1d2239cd0309f9b5038b05462570a5be1, 97a9063518f198ec0adb2ecb89789de342bb8283 |
| Linux/Linuxgeneric | 4.19 | Not reported |
Published upstream
Jul 15, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: tcp: avoid too many retransmit packets If a TCP socket is using TCP_USER_TIMEOUT, and the other peer retracted its window to zero, tcp_retransmit_timer() can retransmit a packet every two jiffies (2 ms for HZ=1000), for about 4 minutes after TCP_USER_TIMEOUT has 'expired'. The fix is to make sure tcp_rtx_probe0_timed_out() takes icsk->icsk_user_timeout into account. Before blamed commit, the socket would not timeout after icsk->icsk_user_timeout, but would use standard exponential backoff for the retransmits. Also worth noting that before commit e89688e3e978 ("net: tcp: fix unexcepted socket die when snd_wnd is 0"), the issue would last 2 minutes instead of 4.
Quoted source text, attributed separately from HOL analysis.