CISA added a serious Linux kernel vulnerability to the List of Known Exploitable Vulnerabilities (KEV) and ordered federal agencies to secure their systems within three weeks.

The vulnerability is tracked as CVE-2024-53104 and was first introduced in kernel version 2.6.26. It was patched by Google for Android users on Monday.
“There are indications that CVE-2024-53104 is subject to a limited, targeted exploit,” the Android security updates warn.
See also: CISA warns of vulnerability in Aviatrix Controllers OS
According to Google, this vulnerability is caused by a weakness in the USB Video Class (UVC) driver, allowing “privilege escalation without requiring additional execution rights.” Google did not provide additional information about the zero-day attacks that exploit this vulnerability.
US federal agencies must protect their networks from attacks targeting vulnerabilities added to CISA's KEV list.
The services have until February 26 to fix the vulnerability in the Linux kernel.
See also: CISA releases guidance on Microsoft's expanded logging capabilities

While CISA's KEV list is primarily designed to alert federal agencies, all organizations should prioritize patching this vulnerability.
The list is very useful for organizations around the world who want to learn about new threats and are interested in better vulnerability management and prioritization.
See also: CISA added BeyondTrust vulnerability to KEV List
Overall, CISA is a great help in protecting and addressing cybersecurity threats. This organization works with various sectors, such as private businesses, governments , and local authorities, to improve the security of digital systems.
It provides information and tools to help organizations protect their networks from cyberattacks and respond to any attacks that may occur. It also informs the public about any vulnerabilities in widely used systems and applications.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
