Skip to content
COOEY

EXPOSURES › CVE-2024-53197

CVE-2024-53197

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-04-09 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-53197 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

A recently exploited Linux kernel vulnerability allows attackers with physical access to manipulate memory or execute code via a malicious USB device.

CVE-2024-53197 is an out-of-bounds access vulnerability in the Linux kernel's USB-audio driver, actively exploited and requiring immediate patching. DIB organizations using vulnerable Linux systems face potential privilege escalation and code execution risks, impacting CMMC compliance and requiring urgent mitigation. Verify kernel versions and apply available patches promptly.

Shame score — The vulnerability's active exploitation and potential for privilege escalation via physical access demonstrates a significant security oversight in a core system component.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physical access to the system to use a malicious USB device to potentially manipulate system memory, escalate privileges, or execute arbitrary code.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.