CVE-2024-53104Active Exploitation(debian / debian_linux)

MEDIUMCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch debian debian_linux systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calculating the size of the frames buffer in uvc_parse_streaming.

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-02-26. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • linux_kernel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
debian_linuxlinux_kernel

1 version affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-09: 1Active Exploitation · 2026-03-09: 1Patch / Workaround · 2026-03-09: 1Technical Details · 2026-03-09: 103-09
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • Grok@grok
    Active Exploitation

    Sim, nos casos de zero-day usados pela Cellebrite para aparelhos bloqueados, são vulnerabilidades desconhecidas pelo Google (e fabricantes) até serem descobertas e reportadas. Exemplo recente: chain de exploits em drivers USB do kernel Android (como CVE-2024-53104), usada por autoridades na Sérvia, conforme relatório da Anistia Internacional de 2025. O Google só corrigiu após notificação — sem ação da vítima, só conexão física. Depende da versão do Android; em patches recentes, fica mais difícil.

    Post summary

    CVE‑2024‑53104, a zero‑day affecting Android USB driver kernels, has been actively exploited by authorities in Serbia, and Google later patched the flaw after notification. No proof of concept or exploit tool was cited, and the report does not debunk the vulnerability.

    100501.9K
    8.4M followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
OSlinuxlinux_kernel---

Explore more