Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Evidence dossier
CVE-2024-53197
ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices
gen-56ccdaf9Normalized restatement
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a bNumConfigurations value that exceeds the initial value used in usb_get_configuration for allocating dev->config. This can lead to out-of-bounds accesses later, e.g. in usb_destroy_configuration.
- State
- PUBLISHED
- Published
- Dec 27, 2024
- Updated
- May 11, 2026
- Evidence coverage
- 85%
2026-07-18 · v2026.06.15 · percentile 88.0%
Distinct CVSS assessments remain side by side; none are averaged.
Source comparison
Who said what
ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices
Linux Kernel Out-of-Bounds Access Vulnerability
Probability 0.035580000000; percentile 0.880320000000
Applicability
Cited product scope
[{"status": "affected", "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2", "lessThan": "0b4ea4bfe16566b84645ded1403756a2dc4e0f19", "versionType": "git"}, {"status": "affected", "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2", "lessThan": "9b8460a2a7ce478e0b625af7c56d444dc24190f7", "versionType": "git"}, {"status": "affected", "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2", "lessThan": "62dc01c83fa71e10446ee4c31e0e3d5d1291e865", "versionType": "git"}, {"status": "affected", "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2", "lessThan": "9887d859cd60727432a01564e8f91302d361b72b", "versionType": "git"}, {"status": "affected", "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2", "lessThan": "920a369a9f014f10ec282fd298d0666129379f1b", "versionType": "git"}, {"status": "affected", "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2", "lessThan": "b8f8b81dabe52b413fe9e062e8a852c48dd0680d", "versionType": "git"}, {"status": "affected", "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2", "lessThan": "379d3b9799d9da953391e973b934764f01e03960", "versionType": "git"}, {"status": "affected", "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2", "lessThan": "b521b53ac6eb04e41c03f46f7fe452e4d8e9bcca", "versionType": "git"}, {"status": "affected", "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2", "lessThan": "b909df18ce2a998afef81d58bbd1a05dc0788c40", "versionType": "git"}]unknown[{"status": "affected", "version": "2.6.12"}, {"status": "unaffected", "version": "0", "lessThan": "2.6.12", "versionType": "semver"}, {"status": "unaffected", "version": "4.19.325", "versionType": "semver", "lessThanOrEqual": "4.19.*"}, {"status": "unaffected", "version": "5.4.287", "versionType": "semver", "lessThanOrEqual": "5.4.*"}, {"status": "unaffected", "version": "5.10.231", "versionType": "semver", "lessThanOrEqual": "5.10.*"}, {"status": "unaffected", "version": "5.15.174", "versionType": "semver", "lessThanOrEqual": "5.15.*"}, {"status": "unaffected", "version": "6.1.120", "versionType": "semver", "lessThanOrEqual": "6.1.*"}, {"status": "unaffected", "version": "6.6.64", "versionType": "semver", "lessThanOrEqual": "6.6.*"}, {"status": "unaffected", "version": "6.11.11", "versionType": "semver", "lessThanOrEqual": "6.11.*"}, {"status": "unaffected", "version": "6.12.2", "versionType": "semver", "lessThanOrEqual": "6.12.*"}, {"status": "unaffected", "version": "6.13", "versionType": "original_commit_for_fix", "lessThanOrEqual": "*"}]unknowncpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*supportedcpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*; start including 2.6.12; end excluding 4.19.325supportedcpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*; start including 4.20; end excluding 5.4.287supportedcpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*; start including 5.5; end excluding 5.10.231supportedcpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*; start including 5.11; end excluding 5.15.174supportedcpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*; start including 5.16; end excluding 6.1.120supportedcpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*; start including 6.2; end excluding 6.6.64supportedcpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*; start including 6.7; end excluding 6.11.11supportedcpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*; start including 6.12; end excluding 6.12.2supportedAssessments
CVSS by origin
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HLimitations and unknowns
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
- NVD-carried upstream facts remain derivative and are not independent corroboration.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Factor D is unknown in Public Core because no accepted canonical mapping-obligation ledger is present.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.