CVE-2024-53104

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calculating the size of the frames buffer in uvc_parse_streaming.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

05 Feb 2025, 20:34

Type Values Removed Values Added
First Time Linux
Linux linux Kernel
References () https://git.kernel.org/stable/c/1ee9d9122801eb688783acd07791f2906b87cb4f - () https://git.kernel.org/stable/c/1ee9d9122801eb688783acd07791f2906b87cb4f - Patch
References () https://git.kernel.org/stable/c/467d84dc78c9abf6b217ada22b3fdba336262e29 - () https://git.kernel.org/stable/c/467d84dc78c9abf6b217ada22b3fdba336262e29 - Patch
References () https://git.kernel.org/stable/c/575a562f7a3ec2d54ff77ab6810e3fbceef2a91d - () https://git.kernel.org/stable/c/575a562f7a3ec2d54ff77ab6810e3fbceef2a91d - Patch
References () https://git.kernel.org/stable/c/622ad10aae5f5e03b7927ea95f7f32812f692bb5 - () https://git.kernel.org/stable/c/622ad10aae5f5e03b7927ea95f7f32812f692bb5 - Patch
References () https://git.kernel.org/stable/c/684022f81f128338fe3587ec967459669a1204ae - () https://git.kernel.org/stable/c/684022f81f128338fe3587ec967459669a1204ae - Patch
References () https://git.kernel.org/stable/c/95edf13a48e75dc2cc5b0bc57bf90d6948a22fe8 - () https://git.kernel.org/stable/c/95edf13a48e75dc2cc5b0bc57bf90d6948a22fe8 - Patch
References () https://git.kernel.org/stable/c/beced2cb09b58c1243733f374c560a55382003d6 - () https://git.kernel.org/stable/c/beced2cb09b58c1243733f374c560a55382003d6 - Patch
References () https://git.kernel.org/stable/c/ecf2b43018da9579842c774b7f35dbe11b5c38dd - () https://git.kernel.org/stable/c/ecf2b43018da9579842c774b7f35dbe11b5c38dd - Patch
References () https://git.kernel.org/stable/c/faff5bbb2762c44ec7426037b3000e77a11d6773 - () https://git.kernel.org/stable/c/faff5bbb2762c44ec7426037b3000e77a11d6773 - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

11 Dec 2024, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: media: uvcvideo: Omitir el análisis de fotogramas de tipo UVC_VS_UNDEFINED en uvc_parse_format Esto puede provocar escrituras fuera de los límites, ya que los fotogramas de este tipo no se tuvieron en cuenta al calcular el tamaño del búfer de fotogramas en uvc_parse_streaming.
CWE CWE-787

02 Dec 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-02 08:15

Updated : 2025-02-06 02:00


NVD link : CVE-2024-53104

Mitre link : CVE-2024-53104

CVE.ORG link : CVE-2024-53104


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-787

Out-of-bounds Write