CVE-2024-53104

HIGH7.8⚠ KEVEPSS 18.0%

Linux Kernel Out-of-Bounds Write Vulnerability

發布日:2024/12/2修改日:2026/4/28加入 CISA KEV 日:2025/2/5

描述

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calculating the size of the frames buffer in uvc_parse_streaming.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

參考連結(1)