Database/Kernel, userspace & hypervisor
Linux kernel (uvcvideo): Out-of-bounds write parsing UVC_VS_UNDEFINED frames - exploited in the wild
CVSS 7.3CVE-2024-53104Kernel, userspace & hypervisorKnown exploitedcurated
Impact
Out-of-bounds write parsing UVC_VS_UNDEFINED frames - exploited in the wild [KEV]
Who can reach it
Local user with USB/device access
What to do
Livepatchable; otherwise drain + reboot. Near-zero exposure on headless GPU servers - deprioritise behind the netfilter set, but it will still show on every compliance scan
References
Related entries
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): Kernel-mode flaw in the 800-series Ethernet Linux driver (anCVE-2025-23241 · Intel ice driver (Ethernet 800 Series, Linux kernel mode)High
- QEMU Guest Agent: symlink and TOCTOU flaws in SSH key injection give root inside the guestCVE-2026-12080 · QEMU Guest Agent (qga) guest-ssh-add-authorized-keys handlerHigh
- Linux kernel (net/xfrm, net/key): No memory corruption here, but a clean namespace boundary break. SA migrationCVE-2026-63914 · Linux kernel (net/xfrm, net/key)High
- zbus_polkit: caller-supplied UID is silently discarded, leaving polkit authorization open to a PID-reuse raceCVE-2026-78422 · zbus_polkit Rust crate (Subject::new_for_owner UID encoding)High
- OpenZFS: ioctl checks accept unprivileged user-namespace capabilities, granting local pool adminCVE-2026-79619 · OpenZFS on Linux (/dev/zfs ioctl privilege checks vs. unprivileged user namespaces)High
- Linux kernel eBPF: syncookie helpers read sk_protocol on mini-sockets without a fullsock checkCVE-2026-80738 · Linux kernel eBPF (bpf_tcp_gen_syncookie / bpf_tcp_check_syncookie helpers)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.