Junglewise Threat Intelligence

CVE-2024-53150: Linux Kernel Out-of-Bounds Read Vulnerability

CVE-2024-53150 · Severity: critical · CVSS 7.1 · Exploited in the wild · Published 2025-04-09

Technologies: Debian Linux, Linux Kernel. Vendors: Debian, Linux.

Executive brief

The Linux kernel USB-audio driver fails to validate the bLength field of descriptors while traversing clock sources. A local attacker can provide a bogus descriptor with a shorter-than-expected length to trigger an out-of-bounds read, potentially leading to sensitive information disclosure or a system crash.

Affected products

  • Linux Linux Kernel up to (excluding) 5.4.287, 5.5 to (excluding) 5.10.231, 5.11 to (excluding) 5.15.174, 5.16 to (excluding) 6.1.120, 6.2 to (excluding) 6.6.64, 6.7 to (excluding) 6.11.11, 6.12 to (excluding) 6.12.2
  • Debian Debian Linux 11.0

Timeline

  • 2025-01-07: disclosed: Initial NIST analysis and CVE publication.
  • 2025-04-09: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
  • 2025-04-09: exploited: Reported as exploited in the wild.

Related threats