We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-53197

ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices



Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a bNumConfigurations value that exceeds the initial value used in usb_get_configuration for allocating dev->config. This can lead to out-of-bounds accesses later, e.g. in usb_destroy_configuration.

Reserved 2024-11-19 | Published 2024-12-27 | Updated 2025-01-20 | Assigner Linux

Product status

Default status
unaffected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before 0b4ea4bfe16566b84645ded1403756a2dc4e0f19
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before 9b8460a2a7ce478e0b625af7c56d444dc24190f7
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before 62dc01c83fa71e10446ee4c31e0e3d5d1291e865
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before 9887d859cd60727432a01564e8f91302d361b72b
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before 920a369a9f014f10ec282fd298d0666129379f1b
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before b8f8b81dabe52b413fe9e062e8a852c48dd0680d
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before 379d3b9799d9da953391e973b934764f01e03960
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before b521b53ac6eb04e41c03f46f7fe452e4d8e9bcca
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before b909df18ce2a998afef81d58bbd1a05dc0788c40
affected

Default status
affected

2.6.12
affected

Any version before 2.6.12
unaffected

4.19.325
unaffected

5.4.287
unaffected

5.10.231
unaffected

5.15.174
unaffected

6.1.120
unaffected

6.6.64
unaffected

6.11.11
unaffected

6.12.2
unaffected

6.13
unaffected

References

git.kernel.org/...c/0b4ea4bfe16566b84645ded1403756a2dc4e0f19

git.kernel.org/...c/9b8460a2a7ce478e0b625af7c56d444dc24190f7

git.kernel.org/...c/62dc01c83fa71e10446ee4c31e0e3d5d1291e865

git.kernel.org/...c/9887d859cd60727432a01564e8f91302d361b72b

git.kernel.org/...c/920a369a9f014f10ec282fd298d0666129379f1b

git.kernel.org/...c/b8f8b81dabe52b413fe9e062e8a852c48dd0680d

git.kernel.org/...c/379d3b9799d9da953391e973b934764f01e03960

git.kernel.org/...c/b521b53ac6eb04e41c03f46f7fe452e4d8e9bcca

git.kernel.org/...c/b909df18ce2a998afef81d58bbd1a05dc0788c40

cve.org (CVE-2024-53197)

nvd.nist.gov (CVE-2024-53197)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-53197

Support options

Helpdesk Chat, Email, Knowledgebase
Subscribe to our newsletter to learn more about our work.