CVE-2024-53197 is a Linux kernel vulnerability in the USB audio subsystem that allows out-of-bounds memory access when handling malicious USB audio devices. The vulnerability requires physical access to connect a malicious USB device and has a LOCAL attack vector, making it unsuitable for internet exploitation.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: OTHER
CVE Published: 2024-12-27
Added to CISA KEV: 2025-04-09 103 DAYS BETWEEN CVE AND KEV
CVE-2024-53197 is a security vulnerability identified in the Linux kernel's USB Audio driver, specifically affecting how it handles certain USB devices [1].
A vulnerability was found in the Linux kernel's USB Audio driver. This flaw allows an attacker with physical access to the system to use a malicious USB device ...
Secure .gov websites use HTTPS A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites. ... CVE-2024-53197 Detail. Description. In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix poteβ¦
... A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. ... kernel: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices (CVE-2024-53197) ...
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a bNumConfigurations value that exceeds the initial value used in usb_get_configuration for allocating dev->config.Links: CVβ¦