⚠ Actively exploited
Added to CISA KEV on 2025-02-05. Federal agencies required to patch by 2025-02-26. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable..
CVE-2024-53104 — Out-of-bounds Write in Linux
Severity
7.8HIGHNVD
OSV8.8OSV6.7OSV6.4OSV6.3OSV5.5OSV4.7
EPSS
14.4%
top 5.56%
CISA KEV
KEV
Added 2025-02-05
Due 2025-02-26
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedDec 2
KEV addedFeb 5
KEV dueFeb 26
Latest updateAug 27
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
In the Linux kernel, the following vulnerability has been resolved:
media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format
This can lead to out of bounds writes since frames of this type were not
taken into account when calculating the size of the frames buffer in
uvc_parse_streaming.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages7 packages
▶CVEListV5linux/linuxc0efd232929c2cd87238de2cccdaf4e845be5b0c — 95edf13a48e75dc2cc5b0bc57bf90d6948a22fe8+9
Also affects: Debian Linux 11.0