EXPOSURES › CVE-2024-53197
CVE-2024-53197
HIGH ⌖ ON CISA KEV · EXPLOITEDA recently exploited Linux kernel vulnerability allows attackers with physical access to manipulate memory or execute code via a malicious USB device.
CVE-2024-53197 is an out-of-bounds access vulnerability in the Linux kernel's USB-audio driver, actively exploited and requiring immediate patching. DIB organizations using vulnerable Linux systems face potential privilege escalation and code execution risks, impacting CMMC compliance and requiring urgent mitigation. Verify kernel versions and apply available patches promptly.
Shame score — The vulnerability's active exploitation and potential for privilege escalation via physical access demonstrates a significant security oversight in a core system component.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physical access to the system to use a malicious USB device to potentially manipulate system memory, escalate privileges, or execute arbitrary code.