Evidence dossier

CVE-2024-53197

ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices

63.378.3Priority evidence range
As known Jul 19, 2026, 5:00 AM UTCgen-56ccdaf9

Normalized restatement

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a bNumConfigurations value that exceeds the initial value used in usb_get_configuration for allocating dev->config. This can lead to out-of-bounds accesses later, e.g. in usb_destroy_configuration.

State
PUBLISHED
Published
Dec 27, 2024
Updated
May 11, 2026
Evidence coverage
85%
CISA KEVCatalog member

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

FIRST EPSS3.56%

2026-07-18 · v2026.06.15 · percentile 88.0%

Source stateNo scored conflict

Distinct CVSS assessments remain side by side; none are averaged.

Source comparison

Who said what

CISA-ADPindependent enrichment
container

CISA ADP Vulnrichment

CVEderivative copy
container

CVE Program Container

Linuxoriginal assertion
container

ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices

CISA KEVoriginal assertion
observed_exploitation

Linux Kernel Out-of-Bounds Access Vulnerability

FIRST EPSSoriginal assertion
model_probability

Probability 0.035580000000; percentile 0.880320000000

Applicability

Cited product scope

Trace impact →
LinuxLinux
[{"status": "affected", "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2", "lessThan": "0b4ea4bfe16566b84645ded1403756a2dc4e0f19", "versionType": "git"}, {"status": "affected", "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2", "lessThan": "9b8460a2a7ce478e0b625af7c56d444dc24190f7", "versionType": "git"}, {"status": "affected", "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2", "lessThan": "62dc01c83fa71e10446ee4c31e0e3d5d1291e865", "versionType": "git"}, {"status": "affected", "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2", "lessThan": "9887d859cd60727432a01564e8f91302d361b72b", "versionType": "git"}, {"status": "affected", "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2", "lessThan": "920a369a9f014f10ec282fd298d0666129379f1b", "versionType": "git"}, {"status": "affected", "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2", "lessThan": "b8f8b81dabe52b413fe9e062e8a852c48dd0680d", "versionType": "git"}, {"status": "affected", "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2", "lessThan": "379d3b9799d9da953391e973b934764f01e03960", "versionType": "git"}, {"status": "affected", "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2", "lessThan": "b521b53ac6eb04e41c03f46f7fe452e4d8e9bcca", "versionType": "git"}, {"status": "affected", "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2", "lessThan": "b909df18ce2a998afef81d58bbd1a05dc0788c40", "versionType": "git"}]unknown
LinuxLinux
[{"status": "affected", "version": "2.6.12"}, {"status": "unaffected", "version": "0", "lessThan": "2.6.12", "versionType": "semver"}, {"status": "unaffected", "version": "4.19.325", "versionType": "semver", "lessThanOrEqual": "4.19.*"}, {"status": "unaffected", "version": "5.4.287", "versionType": "semver", "lessThanOrEqual": "5.4.*"}, {"status": "unaffected", "version": "5.10.231", "versionType": "semver", "lessThanOrEqual": "5.10.*"}, {"status": "unaffected", "version": "5.15.174", "versionType": "semver", "lessThanOrEqual": "5.15.*"}, {"status": "unaffected", "version": "6.1.120", "versionType": "semver", "lessThanOrEqual": "6.1.*"}, {"status": "unaffected", "version": "6.6.64", "versionType": "semver", "lessThanOrEqual": "6.6.*"}, {"status": "unaffected", "version": "6.11.11", "versionType": "semver", "lessThanOrEqual": "6.11.*"}, {"status": "unaffected", "version": "6.12.2", "versionType": "semver", "lessThanOrEqual": "6.12.*"}, {"status": "unaffected", "version": "6.13", "versionType": "original_commit_for_fix", "lessThanOrEqual": "*"}]unknown
Unknown vendorUnknown product
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*supported
Unknown vendorUnknown product
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*; start including 2.6.12; end excluding 4.19.325supported
Unknown vendorUnknown product
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*; start including 4.20; end excluding 5.4.287supported
Unknown vendorUnknown product
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*; start including 5.5; end excluding 5.10.231supported
Unknown vendorUnknown product
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*; start including 5.11; end excluding 5.15.174supported
Unknown vendorUnknown product
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*; start including 5.16; end excluding 6.1.120supported
Unknown vendorUnknown product
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*; start including 6.2; end excluding 6.6.64supported
Unknown vendorUnknown product
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*; start including 6.7; end excluding 6.11.11supported
Unknown vendorUnknown product
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*; start including 6.12; end excluding 6.12.2supported

Assessments

CVSS by origin

7.8
134c704f-9b21-4f2e-91b3-4a467353bcc0CVSS 3.1 · role SecondaryCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
CISA-ADPCVSS 3.1 · role unknownCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Limitations and unknowns

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
  • NVD-carried upstream facts remain derivative and are not independent corroboration.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Factor D is unknown in Public Core because no accepted canonical mapping-obligation ledger is present.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.