vulnerability
Red Hat OpenShift: CVE-2024-53197: kernel: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
5 | (AV:L/AC:L/Au:S/C:N/I:N/A:C) | 2024-12-27 | 2025-03-19 | 2025-04-14 |
Severity
5
CVSS
(AV:L/AC:L/Au:S/C:N/I:N/A:C)
Published
2024-12-27
Added
2025-03-19
Modified
2025-04-14
Description
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices
A bogus device can provide a bNumConfigurations value that exceeds the
initial value used in usb_get_configuration for allocating dev->config.
This can lead to out-of-bounds accesses later, e.g. in
usb_destroy_configuration.
Solution
linuxrpm-upgrade-rhcos
References
- CVE-2024-53197
- https://attackerkb.com/topics/CVE-2024-53197
- REDHAT-RHSA-2025:2473
- REDHAT-RHSA-2025:2474
- REDHAT-RHSA-2025:2475
- REDHAT-RHSA-2025:2476
- REDHAT-RHSA-2025:2488
- REDHAT-RHSA-2025:2489
- REDHAT-RHSA-2025:2490
- REDHAT-RHSA-2025:2501
- REDHAT-RHSA-2025:2510
- REDHAT-RHSA-2025:2512
- REDHAT-RHSA-2025:2514
- REDHAT-RHSA-2025:2517
- REDHAT-RHSA-2025:2524
- REDHAT-RHSA-2025:2525
- REDHAT-RHSA-2025:2528
- REDHAT-RHSA-2025:2627
- REDHAT-RHSA-2025:2646
- REDHAT-RHSA-2025:2696
- REDHAT-RHSA-2025:2701
- REDHAT-RHSA-2025:2705
- REDHAT-RHSA-2025:2710
- REDHAT-RHSA-2025:3055
- REDHAT-RHSA-2025:3301
- REDHAT-RHSA-2025:3573

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.