CVE-2024-50302 KEV
5.5
MEDIUM · CVSS 3.1 · EPSS 0.8% (pctl 55)
Patch first
On CISA KEV — known exploited in the wild, due 2025-03-25.
Description
In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.
Scoring
| CVSS | 5.5 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 0.81% — more likely to be exploited than 55% of all CVEs |
| Weakness | CWE-908 |
| On CISA KEV | yes — remediate by 2025-03-25 |
| Public exploit | none known |
| Published | 2024-11-19 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Linux Kernel Use of Uninitialized Resource Vulnerability |
|---|---|
| Added | 2025-03-04 |
| Due | 2025-03-25 |
| Vendor / product | Linux / Kernel |
| Ransomware use | none reported |
Affected (34)
| Vendor | Product |
|---|---|
| debian | debian linux |
| android | |
| linux | linux kernel |
| siemens | ruggedcom rst2428p |
| siemens | scalance xc316-8 |
| siemens | scalance xc319-4 |
| siemens | scalance xc324-4 |
| siemens | scalance xc324-4eec |
| siemens | scalance xc332 |
| siemens | scalance xc416-8 |
| siemens | scalance xc419-4 |
| siemens | scalance xc424-4 |
| siemens | scalance xc432 |
| siemens | scalance xch328 |
| siemens | scalance xcm324 |
| siemens | scalance xcm328 |
| siemens | scalance xcm332 |
| siemens | scalance xr302-32 |
| siemens | scalance xr322-12 |
| siemens | scalance xr326-8 |
| siemens | scalance xr326-8eec |
| siemens | scalance xr502-32 |
| siemens | scalance xr522-12 |
| siemens | scalance xr524-8c |
| siemens | scalance xr524-8wg |
| siemens | scalance xr526-8 |
| siemens | scalance xr526-8c |
| siemens | scalance xr528-6m |
| siemens | scalance xr552-12m |
| siemens | scalance xrh334 |
| siemens | scalance xrm334 |
| siemens | simatic s7-1500 tm mfp |
| siemens | simatic s7-1500 tm mfp firmware |
| siemens | sinec os |
References
- https://git.kernel.org/stable/c/05ade5d4337867929e7ef664e7ac8e0c734f1aaf
- https://git.kernel.org/stable/c/177f25d1292c7e16e1199b39c85480f7f8815552
- https://git.kernel.org/stable/c/1884ab3d22536a5c14b17c78c2ce76d1734e8b0b
- https://git.kernel.org/stable/c/3f9e88f2672c4635960570ee9741778d4135ecf5
- https://git.kernel.org/stable/c/492015e6249fbcd42138b49de3c588d826dd9648
- https://git.kernel.org/stable/c/9d9f5c75c0c7f31766ec27d90f7a6ac673193191
- https://git.kernel.org/stable/c/d7dc68d82ab3fcfc3f65322465da3d7031d4ab46
- https://git.kernel.org/stable/c/e7ea60184e1e88a3c9e437b3265cbb6439aa7e26
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
- https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html
- https://cert-portal.siemens.com/productcert/html/ssa-355557.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-50302
→ the Explorer · watch your stack · NVD