Database/Kernel, userspace & hypervisor
Linux kernel (ALSA usb-audio): Out-of-bounds access for Extigy/Mbox devices
CVSS 5.8CVE-2024-53197Kernel, userspace & hypervisorKnown exploitedcurated
Impact
Out-of-bounds access for Extigy/Mbox devices; part of a real-world Android forensic-unlock chain [KEV]
Who can reach it
Local user with USB device access
What to do
Livepatchable; otherwise drain + reboot. Physical-access class - matters mainly for colo cages with weak physical controls
References
Related entries
- Linux kernel (ALSA usb-audio): Out-of-bounds read finding clock sourcesCVE-2024-53150 · Linux kernel (ALSA usb-audio)High
- Linux kernel (drivers/pci): Enabling or disabling SR-IOV virtual functions was not serialised against PCI hotplug, soCVE-2025-40219 · Linux kernel (drivers/pci)Medium
- Intel CPU (L1TF / Foreshadow-NG): L1 Terminal Fault: a guest reads any data present in the L1 data cache, includingCVE-2018-3646 · Intel CPU (L1TF / Foreshadow-NG)Medium
- Intel x86-64 CPUs (Ivy Bridge onward); Windows and Linux kernel entry paths: The kernel's syscall/interrupt entry pathCVE-2019-1125 · Intel x86-64 CPUs (Ivy Bridge onward); Windows and Linux kernel entry pathsMedium
- AMD CPU (Branch Type Confusion): Non-Retbleed branch type confusion - speculative cross-domain leakCVE-2022-23825 · AMD CPU (Branch Type Confusion)Medium
- AMD CPU (Retbleed): Retbleed: arbitrary speculative code execution via return instructionsCVE-2022-29900 · AMD CPU (Retbleed)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.