• News/
  • https://www.bleepingcomputer.com/news/security/cisa-orders-agencies-to-patch-linux-kernel-bug-exploited-in-attacks/

CISA orders agencies to patch Linux kernel bug exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Feb 5, 2025
·
Updated

​CISA has ordered federal agencies to secure their systems within three weeks against a high-severity Linux kernel flaw actively exploited in attacks. Tracked as CVE-2024-53104, the security bug was first introduced in kernel version 2.6.26 and was patched by Google for Android users on Monday. "There are indications that CVE-2024-53104 may be under limited, targeted exploitation," the Android February 2025 Android security updates warn. According to Google's security advisory, this vulnerability is caused by an out-of-bounds write weakness in the USB Video Class (UVC) driver, which allows "physical escalation of privilege with no additional execution privileges needed" on unpatched devices. The driver's inability to accurately parse UVC_VS_UNDEFINED frames within the uvc_parse_format function triggers the issue, leading to frame buffer size miscalculations and potential out-of-bounds writes. While Google didn't provide additional information on the zero-day attacks exploiting this vulnerability, the GrapheneOS development team says this USB peripheral driver vulnerability is "likely one of the USB bugs exploited by forensic data extraction tools."

​As mandated by the November 2021 Binding Operational Directive (BOD) 22-01, U.S. federal agencies must secure their networks against ongoing attacks targeting flaws added to CISA's Known Exploited Vulnerabilities catalog. The cybersecurity agency has given Federal Civilian Executive Branch (FCEB) agencies three weeks to patch th...

Read full article

Affected Software

8 affected components
Linux Kernel=2.6.26
Google Android
Apache OFBiz
Microsoft Windows
Microsoft .NET Framework
Microsoft Outlook
Google Android
Linux Kernel=2.6.26
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses CISA's order for federal agencies to patch a high-severity Linux kernel vulnerability.

2

What is the identified vulnerability referenced in the article?

The vulnerability is tracked as CVE-2024-53104 and affects versions of the Linux kernel.

3

How serious is the Linux kernel bug mentioned in the article?

The Linux kernel bug is categorized as high-severity and is actively exploited in attacks.

4

Which systems or software are affected by the vulnerability?

The affected software includes the Linux kernel, Google Android, Apache OFBiz, and various Microsoft products.

5

What action is required from federal agencies regarding this vulnerability?

Federal agencies are required to secure their systems against this vulnerability within three weeks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203