CVE-2024-53104: Linux Kernel Out-of-Bounds Write Vulnerability

Published Dec 2, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

media: uvcvideo: Skip parsing frames of type UVCVSUNDEFINED in uvcparseformat

This can lead to out of bounds writes since frames of this type were not taken into account when calculating the size of the frames buffer in uvcparsestreaming.

Other sources

Linux kernel contains an out-of-bounds write vulnerability in the uvcparsestreaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege.

CISA

This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.

Launchpad

Affected Software

13 affected componentsFixes available
Linux Kernel
Linux Kernel
debian/linux<=5.10.223-1
5.10.234-16.1.129-16.1.135-16.12.27-1
debian/linux-6.1
6.1.129-1~deb11u1
Linux Linux kernel>=2.6.26<4.19.324
Linux Linux kernel>=4.20<5.4.286
Linux Linux kernel>=5.5<5.10.230
Linux Linux kernel>=5.11<5.15.172
Linux Linux kernel>=5.16<6.1.117
Linux Linux kernel>=6.2<6.6.61
Linux Linux kernel>=6.7<6.11.8
Linux Linux kernel>=6.12<6.12.1
Debian Debian Linux=11.0

Remediation

Information

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Mitigation

Block autoloading the uvcvideo module by adding the following line to /etc/modprobe.d/blacklist.conf: blacklist uvcvideo This may disable webcam or prevent it from functioning correctly.

Event History

Dec 4, 2023
News Published
06:01 AM
Dec 18, 2023
News Published
02:25 AM
Jan 15, 2024
News Published
03:34 PM
Apr 29, 2024
News Published
02:29 AM
May 6, 2024
News Published
02:30 AM
May 13, 2024
News Published
02:21 AM
Jun 3, 2024
News Published
12:02 PM
Jul 1, 2024
News Published
03:35 AM
Jul 22, 2024
News Published
03:44 AM
Sep 30, 2024
News Published
03:02 AM
Nov 11, 2024
News Published
03:28 AM
Dec 2, 2024
CVE Published
via MITRE·07:29 AM
Data Sourced
via MITRE·07:29 AM
Description
Data Sourced
via Red Hat·08:00 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·08:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 3, 2025
News Published
via BleepingComputer·08:10 PM
Feb 4, 2025
News Published
via BleepingComputer·05:08 AM
News Published
via The Register·08:18 AM
News Published
via The Register·08:23 AM
Feb 5, 2025
Known Exploited
via CISA·12:00 AM
News Published
via BleepingComputer·06:58 PM
Feb 10, 2025
News Published
02:30 AM
Feb 20, 2025
Data Sourced
via Launchpad·12:51 AM
Description
Feb 28, 2025
News Published
via BleepingComputer·04:27 PM
Mar 3, 2025
News Published
03:31 AM
Mar 4, 2025
News Published
via BleepingComputer·11:38 AM
Apr 7, 2025
News Published
via BleepingComputer·05:55 PM
Apr 29, 2025
Data Sourced
via Ubuntu·01:09 AM
RemedyDescriptionSeverityAffected Software
Sep 8, 2025
News Published
via The Register·11:46 AM

Peer vulnerabilities

Found alongside the following vulnerabilities.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-53104?

CVE-2024-53104 is classified as a high severity vulnerability due to its potential for out of bounds writes.

2

How do I fix CVE-2024-53104?

To fix CVE-2024-53104, you should update your Linux kernel to the patched version that addresses this vulnerability.

3

Which versions of the Linux kernel are affected by CVE-2024-53104?

CVE-2024-53104 affects multiple versions of the Linux kernel before the releases that contain the patch.

4

What are the potential impacts of CVE-2024-53104?

The potential impacts of CVE-2024-53104 include system instability and unauthorized access due to out of bounds memory writes.

5

Is CVE-2024-53104 publicly known?

Yes, CVE-2024-53104 is a publicly disclosed vulnerability affecting the Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203