CVE-2024-53197: Linux Kernel Out-of-Bounds Access Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2025-04-09. EPSS: 4.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a bNumConfigurations value that exceeds the initial value used in usb_get_configuration for allocating dev->config. This can lead to out-of-bounds accesses later, e.g. in usb_destroy_configuration.

Affected products

  • Debian Debian Linux: version 11.0 only
  • Linux Linux Kernel: from 2.6.12, before 4.19.325 (fixed in 4.19.325); from 4.20, before 5.4.287 (fixed in 5.4.287); from 5.5, before 5.10.231 (fixed in 5.10.231); from 5.11, before 5.15.174 (fixed in 5.15.174); from 5.16, before 6.1.120 (fixed in 6.1.120); from 6.2, before 6.6.64 (fixed in 6.6.64); …

Published 2024-12-27. Last modified 2026-06-17.