CVE-2024-53203: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: usb: typec: fix potential array underflow in ucsi_ccg_sync_control() The "command" variable can be controlled by the user via debugfs. The worry is that if con_index is zero then "&uc->ucsi->connector[con_index - 1]" would be an array underflow.

Affected products

  • Linux Linux Kernel: from 5.6, before 6.11.11 (fixed in 6.11.11); from 6.12, before 6.12.2 (fixed in 6.12.2)

Published 2024-12-27. Last modified 2026-06-17.