ZeroHour
CyberScooppublished ()ingested @gregotto

Android security update includes patch for actively exploited vulnerability

criticalVulnerability exploited in the wildimportance 60CVE-2024-53104CVE-2024-45569

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-45569
Memory corruption while parsing the ML IE due to invalid frame content.

Memory corruption while parsing the ML IE due to invalid frame content.

NVD description · AI analysis pending
9.8<1%
  • qualcomm ar8035 firmware
  • qualcomm csr8811 firmware
  • qualcomm fastconnect 6700 firmware
  • +1 more
CVE-2024-53104
Out-of-Bounds Write in Linux Kernel UVC Video Driver (CVE-2024-53104)

CVE-2024-53104 is an out-of-bounds write (CWE-787) in the Linux kernel's uvcvideo (USB Video Class) driver: uvc_parse_format does not skip frames of type UVC_VS_UNDEFINED, but those frame types were not accounted for when sizing the frames buffer in uvc_parse_streaming. The flaw is triggered when the kernel parses format/frame descriptors from a USB camera device, so a crafted or nonconforming USB video descriptor can corrupt adjacent kernel memory. An attacker with local, low-privileged access (CVSS 3.1: AV:L/AC:L/PR:L, 7.8 High) can gain kernel memory corruption with high impact to confidentiality, integrity and availability, typically yielding local privilege escalation. Any Linux system or Android device running a kernel that ships the UVC driver is in scope, including Debian and other distributions built from affected kernel sources. Exploitation is confirmed in the wild: the vulnerability was added to CISA's KEV on 2025-02-05, Google fixed it as an actively exploited flaw in the March 2025 Android Security Update, and EPSS currently estimates a 3.4% (88th percentile) probability of exploitation over the next 30 days.

Do: Upgrade to a Linux kernel version that contains the uvcvideo fix (apply updated kernel packages from your distribution, e.g. Debian), and for Android devices install the March 2025 Android Security Bulletin patches or later. Follow the CISA KEV required action by applying vendor mitigations or discontinuing use if patches are unavailable. To gauge exposure on unpatched hosts, check whether the UVC driver is loaded (e.g. 'lsmod | grep uvcvideo') and restrict untrusted USB video devices until patched.

7.83% KEV
  • Linux kernel (uvcvideo / USB Video Class driver)
  • Debian Linux
masshundreds of millions of Linux/Android installations potentially carrying the vulnerable driver (Linux kernel runs on billions of devices and the UVC driver…
Full article536 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The monthly update closes 47 security vulnerabilities in total.

Listen to this article

0:00

Learn more.

(Photo by Richard Levine/Corbis via Getty Images)

Google has addressed a total of 47 security vulnerabilities in its February update for the Android operating system, highlighted by the patching of a critical flaw that has reportedly been under active exploitation. 

The primary focus of the security update is CVE-2024-53104, a high-severity vulnerability affecting the USB Video Class (UVC) driver in the Linux kernel. First disclosed in November 2024, the flaw, which has a CVSS score of 7.8, enables privilege escalation, allowing malicious actors to execute arbitrary code or cause device crashes. The issue, traced back to the introduction of Linux kernel version 2.6.26 in 2008, is rooted in the mishandling of video frame parsing — specifically an out-of-bounds write condition within the “uvc_parse_format()” function.

Google’s advisory indicates that the flaw is being exploited in a limited, targeted manner. The exploitation involves a form of “physical” privilege escalation, suggestive of potential use by forensic tools aimed at extracting data from older devices.

In addition to CVE-2024-53104, Qualcomm has patched a critical vulnerability in its WLAN components, designated as CVE-2024-45569, which carries a CVSS score of 9.8. This flaw relates to a memory corruption issue arising from improper validation of array indices during network management frame processing, posing a significant risk of remote code execution. Qualcomm’s chipsets are widely used in Android devices. 

Google’s Android security update comprises two patch levels — 2025-02-01 and 2025-02-05 — providing Android partners with flexibility in addressing shared vulnerabilities. The latter patch includes additional remedies for kernel and third-party component vulnerabilities, particularly from vendors such as Arm, Imagination Technologies, MediaTek, and Unisoc.

As always, those using Google Pixel will receive prompt access to the patches, while other manufacturers are often slower to roll out security patches, due to the necessity of tailoring security measures to their own bespoke devices. 

You can read the full bulletin here

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/android-security-update-february-2025/