cbcvebase.
CVE-2024-53149
published 2024-12-24

CVE-2024-53149: In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: glink: fix off-by-one in connector_status UCSI connector's indices start…

PriorityP413medium4.6CVSS 3.1
AVPACLPRNUINSUCNINAH
EPSS
0.30%
23.1th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: glink: fix off-by-one in connector_status UCSI connector's indices start from 1 up to 3, PMIC_GLINK_MAX_PORTS. Correct the condition in the pmic_glink_ucsi_connector_status() callback, fixing Type-C orientation reporting for the third USB-C connector.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.3-1 (forky)linux 6.12.3-1 (forky)
linuxlinux
linuxlinux>= 76716fd5bf09725c2c6825264147f16c21e56853 < 9a5a8b5bd72169aa7a8ec800ef57be2f2cb4d9b29a5a8b5bd72169aa7a8ec800ef57be2f2cb4d9b2
linuxlinux>= 76716fd5bf09725c2c6825264147f16c21e56853 < 6ba6f7f29e0dff47a2799e60dcd1b5c29cd811a56ba6f7f29e0dff47a2799e60dcd1b5c29cd811a5
linuxlinux>= 76716fd5bf09725c2c6825264147f16c21e56853 < 4a22918810980897393fa1776ea3877e4baf8cca4a22918810980897393fa1776ea3877e4baf8cca
linuxlinux>= fd662c37a1087a2631cd2544138650b153e65f90 < 8a2273e5c1beb285729aa001422967b4711c53fe8a2273e5c1beb285729aa001422967b4711c53fe
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 6.10 < 6.11.116.11.11
linuxlinux_kernel>= 6.12 < 6.12.26.12.2

CVSS provenance

nvdv3.14.6MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv4.6MEDIUM
vendor_debian4.6LOW
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.