CVE-2024-53150 is a Linux kernel vulnerability in the USB audio driver that allows out-of-bounds reads when processing malicious USB device descriptors. Despite being in CISA KEV, this is primarily a local privilege escalation issue requiring physical USB device insertion or prior system access.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: OTHER
CVE Published: 2024-12-24
Added to CISA KEV: 2025-04-09 106 DAYS BETWEEN CVE AND KEV
CVE-2024-53150 is a vulnerability identified in the Linux kernel's USB Audio driver, specifically involving an out-of-bounds read issue when the driver traverses clock descriptors [3] [1].
Below is the requested information regarding this vulnerability:
A vulnerability was found in the Linux kernel's USB Audio driver. This flaw can allow an attacker with physical access to the system to use a malicious USB ...
... A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. ... kernel: ALSA: usb-audio: Fix out of bounds reads when finding clock sources (CVE-2024-53150) ... BZ - 2333971โฆ
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio ...
... A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. ... kernel: ALSA: usb-audio: Fix out of bounds reads when finding clock sources (CVE-2024-53150) ... BZ - 2333971โฆ