Executive brief
The Linux kernel's USB Video Class (UVC) driver contains an out-of-bounds write vulnerability in uvc_parse_streaming. The issue arises because the driver fails to skip frames of type UVC_VS_UNDEFINED during parsing, leading to incorrect buffer size calculations in uvc_parse_format.
Affected products
- Linux Linux Kernel 2.6.26 to 4.19.324, 4.20 to 5.4.286, 5.5 to 5.10.230, 5.11 to 5.15.172, 5.16 to 6.1.117, 6.2 to 6.6.61, 6.7 to 6.11.8, 6.12 to 6.12.1
- Debian Debian Linux 11.0
Timeline
- 2025-02-05: disclosed
- 2025-02-05: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-02-05: exploited: Reported as exploited in the wild per CISA KEV entry.