logo

CISA orders agencies to patch Linux kernel bug exploited in attacks

ID: 57e9cf95-440f-58e8-9746-685228a50a30

STIX ID: report--57e9cf95-440f-58e8-9746-685228a50a30

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-02-05

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA has ordered federal agencies to urgently patch a high-severity Linux kernel/Android zero-day (CVE-2024-53104) — an out-of-bounds write in the UVC driver that can enable privilege escalation via USB peripherals. Google released fixes for Android, reports indicate limited targeted exploitation, and GrapheneOS suggests the flaw may be leveraged by forensic extraction tools; CISA added the issue to its Known Exploited Vulnerabilities catalog and set a three-week remediation deadline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.