CVE-2024-53203

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Dec 27, 2024
Updated: Jan 16, 2025
CWE ID 129

Summary

CVE-2024-53203 is a newly identified vulnerability in the Linux kernel. This issue affects the type-C USB controller, and specifically, the ucsi_ccg_sync_control() function. An array underflow can occur if the user controls the "command" variable via debugfs, and con_index is zero. This vulnerability has been resolved in the latest kernel update. If exploited, it could lead to unintended behavior or crashes, potentially providing an attacker with an entry point for more serious attacks. Users are urged to update their Linux kernels as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share