{
    "id": "CVE-2024-50302",
    "published": "2024-11-19 02:16:32",
    "last_modified": "2026-06-17 08:04:10",
    "cvss_score": "5.5",
    "cvss_severity": "MEDIUM",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
    "cwe": "CWE-908",
    "description": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: zero-initialize the report buffer\n\nSince the report buffer is used by all kinds of drivers in various ways, let's\nzero-initialize it during allocation to make sure that it can't be ever used\nto leak kernel memory via specially-crafted report.",
    "epss_score": "0.00811",
    "epss_percentile": "0.55203",
    "kev": 1,
    "kev_due": "2025-03-25",
    "has_exploit": 0,
    "updated_at": "2026-09-26 18:36:15",
    "priority": {
        "rank": 1,
        "label": "Patch first",
        "why": "On CISA KEV — known exploited in the wild, due 2025-03-25."
    },
    "products": [
        {
            "vendor": "debian",
            "product": "debian_linux"
        },
        {
            "vendor": "google",
            "product": "android"
        },
        {
            "vendor": "linux",
            "product": "linux_kernel"
        },
        {
            "vendor": "siemens",
            "product": "ruggedcom_rst2428p"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xc316-8"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xc319-4"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xc324-4"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xc324-4eec"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xc332"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xc416-8"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xc419-4"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xc424-4"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xc432"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xch328"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xcm324"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xcm328"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xcm332"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xr302-32"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xr322-12"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xr326-8"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xr326-8eec"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xr502-32"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xr522-12"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xr524-8c"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xr524-8wg"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xr526-8"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xr526-8c"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xr528-6m"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xr552-12m"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xrh334"
        },
        {
            "vendor": "siemens",
            "product": "scalance_xrm334"
        },
        {
            "vendor": "siemens",
            "product": "simatic_s7-1500_tm_mfp"
        },
        {
            "vendor": "siemens",
            "product": "simatic_s7-1500_tm_mfp_firmware"
        },
        {
            "vendor": "siemens",
            "product": "sinec_os"
        }
    ],
    "kev_detail": {
        "cve_id": "CVE-2024-50302",
        "date_added": "2025-03-04",
        "due_date": "2025-03-25",
        "vendor": "Linux",
        "product": "Kernel",
        "name": "Linux Kernel Use of Uninitialized Resource Vulnerability",
        "ransomware": 0
    },
    "exploits": [],
    "refs_list": [
        "https://git.kernel.org/stable/c/05ade5d4337867929e7ef664e7ac8e0c734f1aaf",
        "https://git.kernel.org/stable/c/177f25d1292c7e16e1199b39c85480f7f8815552",
        "https://git.kernel.org/stable/c/1884ab3d22536a5c14b17c78c2ce76d1734e8b0b",
        "https://git.kernel.org/stable/c/3f9e88f2672c4635960570ee9741778d4135ecf5",
        "https://git.kernel.org/stable/c/492015e6249fbcd42138b49de3c588d826dd9648",
        "https://git.kernel.org/stable/c/9d9f5c75c0c7f31766ec27d90f7a6ac673193191",
        "https://git.kernel.org/stable/c/d7dc68d82ab3fcfc3f65322465da3d7031d4ab46",
        "https://git.kernel.org/stable/c/e7ea60184e1e88a3c9e437b3265cbb6439aa7e26",
        "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html",
        "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html",
        "https://cert-portal.siemens.com/productcert/html/ssa-265688.html",
        "https://cert-portal.siemens.com/productcert/html/ssa-355557.html",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-50302"
    ]
}