⚠ Actively exploited
Added to CISA KEV on 2025-02-05. Federal agencies required to patch by 2025-02-26. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable..

CVE-2024-53104Out-of-bounds Write in Linux

CWE-787Out-of-bounds Write105 documents11 sources
Severity
7.8HIGHNVD
OSV8.8OSV6.7OSV6.4OSV6.3OSV5.5OSV4.7
EPSS
14.4%
top 5.56%
CISA KEV
KEV
Added 2025-02-05
Due 2025-02-26
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedDec 2
KEV addedFeb 5
KEV dueFeb 26
Latest updateAug 27
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calculating the size of the frames buffer in uvc_parse_streaming.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages7 packages

NVDlinux/linux_kernel2.6.264.19.324+7
Debianlinux/linux_kernel< 5.10.234-1+3
Ubuntulinux/linux_kernel< 5.4.0-208.228+11
CVEListV5linux/linuxc0efd232929c2cd87238de2cccdaf4e845be5b0c95edf13a48e75dc2cc5b0bc57bf90d6948a22fe8+9
debiandebian/linux< linux 6.1.119-1 (bookworm)

Also affects: Debian Linux 11.0

Patches

🔴Vulnerability Details

51
OSV
linux vulnerabilities2025-08-27
OSV
linux-raspi-5.4 vulnerabilities2025-05-28
OSV
linux-raspi vulnerabilities2025-05-28
OSV
linux-azure-nvidia vulnerabilities2025-04-28
OSV
linux-ibm-5.15 vulnerabilities2025-04-24

📋Vendor Advisories

50
Ubuntu
Linux kernel vulnerabilities2025-08-27
CISA ICS
Siemens Third-Party Components in SINEC OS2025-08-14
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2025-05-28
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2025-05-28
Ubuntu
Linux kernel (Azure, N-Series) vulnerabilities2025-04-28

🕵️Threat Intelligence

3
Bleepingcomputer
Google fixes Android zero-days exploited in attacks, 60 other flaws2025-04-07
Bleepingcomputer
Google fixes Android zero-day exploited by Serbian authorities2025-03-04
Bleepingcomputer
CISA orders agencies to patch Linux kernel bug exploited in attacks2025-02-05