← Back to CVE List
Vulnerability Intelligence Report
ALSA: usb-audio: Fix out of bounds reads when finding clock sources

CVE-2024-53150

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't check bLength of each descriptor at traversing for clock descriptors. That is, when a device provides a bogus descriptor with a shorter bLength, the driver might hit out-of-bounds reads. For addressing it, this patch adds sanity checks to the validator functions for the clock descriptor traversal. When the descriptor length is shorter than expected, it's skipped in the loop. For the clock source and clock multiplier descriptors, we can just check bLength against the sizeof() of each descriptor type. OTOH, the clock selector descriptor of UAC2 and UAC3 has an array of bNrInPins elements and two more fields at its tail, hence those have to be checked in addition to the sizeof() check.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
7.1
HIGH
Exploitability:1.9
Impact Score:5.2
EPSS Probability:1.32%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-125 ↗CWE-125 Out-of-bounds Read

Affected Products & Versions

Vendor Product Affected Versions
Linux Linux b8e4f1fdfa422398c2d6c47bfb7d1feb3046d70a < a632bdcb359fd8145e86486ff8612da98e239acd (affected), b8e4f1fdfa422398c2d6c47bfb7d1feb3046d70a < 45a92cbc88e4013bfed7fd2ccab3ade45f8e896b (affected), b8e4f1fdfa422398c2d6c47bfb7d1feb3046d70a < ab011f7439d9bbfd34fd3b9cef4b2d6d952c9bb9 (affected), b8e4f1fdfa422398c2d6c47bfb7d1feb3046d70a < da13ade87a12dd58829278bc816a61bea06a56a9 (affected), b8e4f1fdfa422398c2d6c47bfb7d1feb3046d70a < 74cb86e1006c5437b1d90084d22018da30fddc77 (affected), b8e4f1fdfa422398c2d6c47bfb7d1feb3046d70a < ea0fa76f61cf8e932d1d26e6193513230816e11d (affected), b8e4f1fdfa422398c2d6c47bfb7d1feb3046d70a < 096bb5b43edf755bc4477e64004fa3a20539ec2f (affected), b8e4f1fdfa422398c2d6c47bfb7d1feb3046d70a < a3dd4d63eeb452cfb064a13862fb376ab108f6a6 (affected), 9feeaa50e5b4b0b71259d918a36ecf9059e60796 (affected), 3b17a13b687ae99939dc94a4ae01fbc34f68decc (affected), 4.19.84 < 4.20 (affected), 5.3.11 < 5.4 (affected)
Linux Linux 5.4 (affected), 0 < 5.4 (unaffected), 5.4.287 <= 5.4.* (unaffected), 5.10.231 <= 5.10.* (unaffected), 5.15.174 <= 5.15.* (unaffected), 6.1.120 <= 6.1.* (unaffected), 6.6.64 <= 6.6.* (unaffected), 6.11.11 <= 6.11.* (unaffected), 6.12.2 <= 6.12.* (unaffected), 6.13 <= * (unaffected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
1.325%

Identity & Timeline

StatusPUBLISHED
Assigning Authoritykernel.org · Vendor · USA
Reserved2024-11-19T17:17:24
Published2024-12-24T11:28:50
Last Updated2026-05-23T15:55:17

LINK COPIED TO CLIPBOARD