FlawAtlas
Search the atlas
CVE-2024-53104 High

Confirmed as exploited

media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calculating the size of the frames buffer in uvc_parse_streaming.

Exploit probability 3.3%
Published December 2, 2024
Required by February 26, 2025
Last source change August 12, 2026

01 / ACTION

Required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

02 / AFFECTED SOFTWARE

Affected packages

Linux Kernel
Unknown Unknown
Android :linux_kernel:

1 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related USN-7276-1
related USN-7277-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities ASB-A-378455392

In uvc_parse_format of uvc_driver.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

View original source
Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities CVE-2024-53104

Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege.

View original source
Open Source Vulnerabilities CVE-2024-53104

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calculating the size of the frames buffer in uvc_parse_streaming.

View original source

05 / REFERENCES

Further evidence