CVE CVE

CVE-2024-53104

CISA Known Exploited Vulnerability (KEV)

Linux Kernel Out-of-Bounds Write Vulnerability

February 5, 2025

February 26, 2025

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

In the Linux kernel, the following vulnerability has been resolved:

media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format

This can lead to out of bounds writes since frames of this type were not
taken into account when calculating the size of the frames buffer in
uvc_parse_streaming.

Weakness Enumeration

CWE-ID CWE Name

CWE-787
Out-of-bounds Write

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
7.8
Severity:

HIGH

Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2

Not defined