CVE-2024-53197

Linux Kernel: Out-of-Bounds Access

As of , CVE-2024-53197 in Linux Kernel is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch soon.

Exploited
Yes: CISA listed it on 9 April 2025
US federal deadline
30 April 202521 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.04Higher than 90% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
Vendor advice: lore.kernel.org and source.android.comLinks below, from CISA's entry.

What CISA says to do

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA's required action

What the flaw is

Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physical access to the system to use a malicious USB device to potentially manipulate system memory, escalate privileges, or execute arbitrary code.

CISA's description

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a bNumConfigurations value that exceeds the initial value used in usb_get_configuration for allocating dev->config. This can lead to out-of-bounds accesses later, e.g. in usb_destroy_configuration.

The CVE record's description, from Linux

CVE published
27 December 2024
Assigned by
Linux
CVSS
7.8 High (CVSS 3.1, from CISA-ADP)
CWE-787
Out-of-bounds Write
CISA SSVC, exploitation
active
CISA SSVC, automatable
no
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

Kernel: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-39682Improper Check for Unusual or Exceptional ConditionsLinux KernelPatch nowForensic triage required by CISA0.03
CVE-2025-39964Race ConditionLinux KernelPatch nowForensic triage required by CISA0.01
CVE-2026-53266Out-of-Bounds WriteLinux KernelPatch nowForensic triage required by CISA0.01
CVE-2026-53362UnspecifiedLinux KernelPatch nowForensic triage required by CISA0.01
CVE-2021-22555Heap Out-of-Bounds WriteLinux KernelPatch this weekMetasploit module; EPSS 0.79; verified Exploit-DB entry0.79
CVE-2013-6282Improper Input ValidationLinux KernelPatch this weekMetasploit module; verified Exploit-DB entry0.40
CVE-2019-13272Improper Privilege ManagementLinux KernelPatch this weekMetasploit module; EPSS 0.52; verified Exploit-DB entry0.52
CVE-2010-3904Improper Input ValidationLinux KernelPatch this weekMetasploit module; verified Exploit-DB entry0.16
CVE-2022-0847Privilege EscalationLinux KernelPatch this weekMetasploit module; EPSS 0.930.93
CVE-2021-3493Privilege EscalationLinux KernelPatch this weekMetasploit module0.49

All 31 entries for Kernel

Read further