CISA orders agencies to patch Linux kernel bug exploited in attacks
ID: 57e9cf95-440f-58e8-9746-685228a50a30
STIX ID: report--57e9cf95-440f-58e8-9746-685228a50a30
Feed Name: Bleeping Computer
CISA has ordered federal agencies to urgently patch a high-severity Linux kernel/Android zero-day (CVE-2024-53104) — an out-of-bounds write in the UVC driver that can enable privilege escalation via USB peripherals. Google released fixes for Android, reports indicate limited targeted exploitation, and GrapheneOS suggests the flaw may be leveraged by forensic extraction tools; CISA added the issue to its Known Exploited Vulnerabilities catalog and set a three-week remediation deadline.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
