CVE-2024-53104

HIGH CISA KEV EPSS 87.0%
Published Dec 2, 20241y ago · Modified Jun 17, 20262w ago
7.8 CVSS 3.1
High
Find Similar
Published Dec 2, 2024 1y ago
Last Modified Jun 17, 2026 2w ago
KEV Listed Feb 5, 2025 1y ago
KEV Due Feb 26, 2025 494d overdue

Description

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calculating the size of the frames buffer in uvc_parse_streaming.

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

CISA Known Exploited Overdue 494d
Added
Feb 5, 2025
Due
Feb 26, 2025

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

EPSS Exploit Probability
87.0% percentile
Exploit & Patch Status
Actively Exploited (KEV)
Patch Available

Weaknesses 1

CWE-787 Out-of-bounds Write Memory Safety

Affected Products 9

VendorProductVersionRange
debiandebian_linux11.0any
linuxlinux_kernel*≥2.6.26  –  <4.19.324
linuxlinux_kernel*≥4.20  –  <5.4.286
linuxlinux_kernel*≥5.5  –  <5.10.230
linuxlinux_kernel*≥5.11  –  <5.15.172
linuxlinux_kernel*≥5.16  –  <6.1.117
linuxlinux_kernel*≥6.2  –  <6.6.61
linuxlinux_kernel*≥6.7  –  <6.11.8
linuxlinux_kernel*≥6.12  –  <6.12.1

References 12

  • git.kernel.org https://git.kernel.org/stable/c/1ee9d9122801eb688783acd07791f2906b87cb4f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/467d84dc78c9abf6b217ada22b3fdba336262e29
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/575a562f7a3ec2d54ff77ab6810e3fbceef2a91d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/622ad10aae5f5e03b7927ea95f7f32812f692bb5
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/684022f81f128338fe3587ec967459669a1204ae
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/95edf13a48e75dc2cc5b0bc57bf90d6948a22fe8
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/beced2cb09b58c1243733f374c560a55382003d6
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ecf2b43018da9579842c774b7f35dbe11b5c38dd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/faff5bbb2762c44ec7426037b3000e77a11d6773
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
    Mailing List
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html
    Mailing List
  • cisa.gov https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-53104
    US Government Resource

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/1ee9d9122801eb688783acd07791f2906b87cb4f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/467d84dc78c9abf6b217ada22b3fdba336262e29
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/575a562f7a3ec2d54ff77ab6810e3fbceef2a91d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/622ad10aae5f5e03b7927ea95f7f32812f692bb5
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/684022f81f128338fe3587ec967459669a1204ae
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/95edf13a48e75dc2cc5b0bc57bf90d6948a22fe8
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/beced2cb09b58c1243733f374c560a55382003d6
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ecf2b43018da9579842c774b7f35dbe11b5c38dd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/faff5bbb2762c44ec7426037b3000e77a11d6773
    Patch