CVE-2024-50302
MEDIUM CISA KEVDescription
In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.
Is your site exposed to CVE-2024-50302?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| android | |
| debian | debian_linux |
| siemens | simatic_s7-1500_tm_mfp_firmware |
| siemens | simatic_s7-1500_tm_mfp |
| siemens | sinec_os |
| siemens | ruggedcom_rst2428p |
| siemens | scalance_xc316-8 |
| siemens | scalance_xc319-4 |
| siemens | scalance_xc324-4 |
| siemens | scalance_xc324-4eec |
| siemens | scalance_xc332 |
| siemens | scalance_xc416-8 |
| siemens | scalance_xc419-4 |
| siemens | scalance_xc424-4 |
| siemens | scalance_xc432 |
| siemens | scalance_xch328 |
| siemens | scalance_xcm324 |
| siemens | scalance_xcm328 |
| siemens | scalance_xcm332 |
| siemens | scalance_xr302-32 |
| siemens | scalance_xr322-12 |
| siemens | scalance_xr326-8 |
| siemens | scalance_xr326-8eec |
| siemens | scalance_xr502-32 |
| siemens | scalance_xr522-12 |
| siemens | scalance_xr524-8c |
| siemens | scalance_xr524-8wg |
| siemens | scalance_xr526-8 |
| siemens | scalance_xr526-8c |
| siemens | scalance_xr528-6m |
| siemens | scalance_xr552-12m |
| siemens | scalance_xrh334 |
| siemens | scalance_xrm334 |
| linux | linux_kernel |
| linux | linux_kernel |
| linux | linux_kernel |
| linux | linux_kernel |
| linux | linux_kernel |
| linux | linux_kernel |
| linux | linux_kernel |
| linux | linux_kernel |
| linux | linux_kernel |
| linux | linux_kernel |
| linux | linux_kernel |
| linux | linux_kernel |
| linux | linux_kernel |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2024-50302? +
How severe is CVE-2024-50302? +
What products are affected by CVE-2024-50302? +
How do I check if I'm vulnerable to CVE-2024-50302? +
Related Vulnerabilities
In high traffic environments, a Silicon Labs OpenThread RCP (see impacted versions) fails to clear the SPI transmit buffer and …
Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a uninitialized kernel …
The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct. It did not first zero …
The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did not first zero the …
To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the current time for the timer's clock. For …
When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremented the iovec index for every mbuf …