Database/Kernel, userspace & hypervisor
Linux kernel (ALSA usb-audio): Out-of-bounds read finding clock sources
CVSS 7.1CVE-2024-53150Kernel, userspace & hypervisorKnown exploitedcurated
Impact
Out-of-bounds read finding clock sources [KEV]
Who can reach it
Local user with USB device access
What to do
Livepatchable; otherwise drain + reboot. Blacklist snd-usb-audio on servers
References
Related entries
- Linux kernel (ALSA usb-audio): Out-of-bounds access for Extigy/Mbox devicesCVE-2024-53197 · Linux kernel (ALSA usb-audio)Medium
- VMware ESXi / Workstation / Fusion: Out-of-bounds read in HGFS leaks vmx process memory to the guestCVE-2025-22226 · VMware ESXi / Workstation / FusionHigh
- Linux kernel i40e: out-of-bounds read through the netdev_ops debugfs fileCVE-2025-39901 · Linux kernel i40e driver (netdev_ops debugfs file)High
- Linux kernel (arch/x86/kvm/svm): On AMD hosts that cannot report the next RIP, KVM's WRMSR/HLT/INVD fastpath has toCVE-2025-40038 · Linux kernel (arch/x86/kvm/svm)High
- VMware ESXi / Workstation / Tools: Uninitialised memory in vSockets discloses host memory to the guestCVE-2025-41239 · VMware ESXi / Workstation / ToolsHigh
- PackageKit dnf5 backend: an unprivileged local user can uninstall packages under a simulate flagCVE-2026-19816 · PackageKit dnf5 backend (RepoRemove polkit bypass)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.