← Global Threat Landscape

CVE-2024-53150

CWE-125

High

74.4

RPS

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't check bLength of each descriptor at traversing for clock descriptors. That is, when a device provides a bogus descriptor with a shorter bLength, the driver might hit out-of-bounds reads. For addressing it, this patch adds sanity checks to the validator functions for the clock descriptor traversal. When the descriptor length is shorter than expected, it's skipped in the loop. For the clock source and clock multiplier descriptors, we can just check bLength against the sizeof() of each descriptor type. OTOH, the clock selector descriptor of UAC2 and UAC3 has an array of bNrInPins elements and two more fields at its tail, hence those have to be checked in addition to the sizeof() check.

Source: NVD

Signals

CVSS
7.1
High · v3.1
EPSS
1.35%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Apr 2025
Fix commit
No known fix commit
Sources: MoreFixes, FreshFixes
Weakness
CWE-125
Published
24 Dec 2024
Last modified 4 Nov 2025

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2024-53150

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2024-53150 · RPS 74.4 · DevSecure Intelligence