CVE-2024-53104
In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calculating the size of the frames buffer in uvc_parse_streaming.
- Affected products
- Alt Linux, Almalinux, Astra Linux, Centos, Debian, Linuxmint, Linux Kernel, Red Hat
- Debian Debian Linux
- = 11.0
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 3.4% (88th percentile)
- Weakness
- CWE-787
- NVD status
- Analyzed
- Published
- 2024-12-02
CVE-2024-53104 at NVD
2 known exploits for CVE-2024-53104
Proof-of-concept code and exploit modules indexed by Sploitus