CVE-2024-53150

Updated: 2026-01-16 03:29:01.648547

Description:

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't check bLength of each descriptor at traversing for clock descriptors. That is, when a device provides a bogus descriptor with a shorter bLength, the driver might hit out-of-bounds reads. For addressing it, this patch adds sanity checks to the validator functions for the clock descriptor traversal. When the descriptor length is shorter than expected, it's skipped in the loop. For the clock source and clock multiplier descriptors, we can just check bLength against the sizeof() of each descriptor type. OTOH, the clock selector descriptor of UAC2 and UAC3 has an array of bNrInPins elements and two more fields at its tail, hence those have to be checked in addition to the sizeof() check.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.1

Known exploits

Added Date Description Due Date Notes
2025-04-09 Linux Kernel contains an out-of-bounds read vulnerability in the USB-audio driver that allows a local, privileged attacker to obtain potentially sensitive information. 2025-04-30 This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://lore.kernel.org/linux-cve-announce/2024122427-CVE-2024-53150-3a7d@gregkh/ ; https://source.android.com/docs/security/bulletin/2025-04-01 ; https://nvd.nist.gov/vuln/detail/CVE-2024-53150

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.1 HIGH Released CLSA-2025:1743193221 2025-02-05 02:17:36
CentOS 6 ELS kernel 2.6.32 7.1 HIGH Released CLSA-2025:1740656525 2025-03-12 23:16:27
CentOS 7 ELS kernel 3.10.0 7.1 HIGH Released CLSA-2025:1740649075 2025-03-14 23:28:25
CentOS 8.4 ELS kernel 4.18.0 7.1 HIGH Released CLSA-2025:1757961864 2025-09-16 02:04:45
CentOS 8.5 ELS kernel 4.18.0 7.1 HIGH Released CLSA-2025:1757962453 2025-09-16 02:04:46
CentOS Stream 8 ELS kernel 4.18.0 7.1 HIGH Released CLSA-2025:1738592614 2025-02-04 02:15:09
CloudLinux 6 ELS kernel 2.6.32 7.1 HIGH Ignored 2025-09-23 09:34:08 Postponed until request or high risk detected
CloudLinux 7 ELS kernel 3.10.0 7.1 HIGH Ignored 2025-11-08 00:58:49 CloudLinux 6 and 7 support is limited and provided on demand. We strongly recommend upgrading to Clo...
Oracle Linux 6 ELS kernel 2.6.32 7.1 HIGH Released CLSA-2025:1740598467 2025-02-26 21:54:32
Oracle Linux 7 ELS kernel 3.10.0 7.1 HIGH Released CLSA-2025:1742322442 2025-03-25 03:29:15
Total: 17