Junglewise Threat Intelligence

CVE-2024-53104: Linux Kernel Out-of-Bounds Write Vulnerability

CVE-2024-53104 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2025-02-05

Technologies: Linux Kernel, Debian Linux. Vendors: Linux, Debian.

Executive brief

The Linux kernel's USB Video Class (UVC) driver contains an out-of-bounds write vulnerability in uvc_parse_streaming. The issue arises because the driver fails to skip frames of type UVC_VS_UNDEFINED during parsing, leading to incorrect buffer size calculations in uvc_parse_format.

Affected products

  • Linux Linux Kernel 2.6.26 to 4.19.324, 4.20 to 5.4.286, 5.5 to 5.10.230, 5.11 to 5.15.172, 5.16 to 6.1.117, 6.2 to 6.6.61, 6.7 to 6.11.8, 6.12 to 6.12.1
  • Debian Debian Linux 11.0

Timeline

  • 2025-02-05: disclosed
  • 2025-02-05: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-02-05: exploited: Reported as exploited in the wild per CISA KEV entry.

Related threats