CVE-2024-53104

HIGH7.8⚠ KEVEPSS 18.0%

Linux Kernel Out-of-Bounds Write Vulnerability

Published: 12/2/2024Modified: 4/28/2026Added to CISA KEV: 2/5/2025

Description

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calculating the size of the frames buffer in uvc_parse_streaming.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References (1)