cbcvebase.
CVE-2024-53061
published 2024-11-19

CVE-2024-53061: In the Linux kernel, the following vulnerability has been resolved: media: s5p-jpeg: prevent buffer overflows The current logic allows word to be less than 2…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.30%
22.8th percentile
In the Linux kernel, the following vulnerability has been resolved: media: s5p-jpeg: prevent buffer overflows The current logic allows word to be less than 2. If this happens, there will be buffer overflows, as reported by smatch. Add extra checks to prevent it. While here, remove an unused word = 0 assignment.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux
linuxlinux>= 6c96dbbc2aa9f5b4aed8792989d69eae22bf77c4 < c5f6fefcda8fac8f082b6c5bf416567f4e100c51c5f6fefcda8fac8f082b6c5bf416567f4e100c51
linuxlinux>= 6c96dbbc2aa9f5b4aed8792989d69eae22bf77c4 < e5117f6e7adcf9fd7546cdd0edc9abe4474bc98be5117f6e7adcf9fd7546cdd0edc9abe4474bc98b
linuxlinux>= 6c96dbbc2aa9f5b4aed8792989d69eae22bf77c4 < f54e8e1e39dacccebcfb9a9a36f0552a0a97e2eff54e8e1e39dacccebcfb9a9a36f0552a0a97e2ef
linuxlinux>= 6c96dbbc2aa9f5b4aed8792989d69eae22bf77c4 < a930cddfd153b5d4401df0c01effa14c831ff21ea930cddfd153b5d4401df0c01effa14c831ff21e
linuxlinux>= 6c96dbbc2aa9f5b4aed8792989d69eae22bf77c4 < c85db2d4432de4ff9d97006691ce2dcb5bda660ec85db2d4432de4ff9d97006691ce2dcb5bda660e
linuxlinux>= 6c96dbbc2aa9f5b4aed8792989d69eae22bf77c4 < 784bc785a453eb2f8433dd62075befdfa1b2d6fd784bc785a453eb2f8433dd62075befdfa1b2d6fd
linuxlinux>= 6c96dbbc2aa9f5b4aed8792989d69eae22bf77c4 < c951a0859fdacf49a2298b5551a7e52b95ff6f51c951a0859fdacf49a2298b5551a7e52b95ff6f51
linuxlinux>= 6c96dbbc2aa9f5b4aed8792989d69eae22bf77c4 < 14a22762c3daeac59a5a534e124acbb4d7a79b3a14a22762c3daeac59a5a534e124acbb4d7a79b3a
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-133.1445.15.0-133.144
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 4.20 < 5.4.2865.4.286
linuxlinux_kernel>= 4.4 < 4.19.3244.19.324
linuxlinux_kernel>= 5.11 < 5.15.1725.15.172
linuxlinux_kernel>= 5.16 < 6.1.1176.1.117
linuxlinux_kernel>= 5.5 < 5.10.2305.10.230

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.