← Back to CVE List
Vulnerability Intelligence Report
HID: core: zero-initialize the report buffer

CVE-2024-50302

In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
5.5
MEDIUM
Exploitability:1.9
Impact Score:3.6
EPSS Probability:0.81%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-908 ↗CWE-908 Use of Uninitialized Resource

Affected Products & Versions

Vendor Product Affected Versions
Linux Linux 27ce405039bfe6d3f4143415c638f56a3df77dca < e7ea60184e1e88a3c9e437b3265cbb6439aa7e26 (affected), 27ce405039bfe6d3f4143415c638f56a3df77dca < 3f9e88f2672c4635960570ee9741778d4135ecf5 (affected), 27ce405039bfe6d3f4143415c638f56a3df77dca < d7dc68d82ab3fcfc3f65322465da3d7031d4ab46 (affected), 27ce405039bfe6d3f4143415c638f56a3df77dca < 05ade5d4337867929e7ef664e7ac8e0c734f1aaf (affected), 27ce405039bfe6d3f4143415c638f56a3df77dca < 1884ab3d22536a5c14b17c78c2ce76d1734e8b0b (affected), 27ce405039bfe6d3f4143415c638f56a3df77dca < 9d9f5c75c0c7f31766ec27d90f7a6ac673193191 (affected), 27ce405039bfe6d3f4143415c638f56a3df77dca < 492015e6249fbcd42138b49de3c588d826dd9648 (affected), 27ce405039bfe6d3f4143415c638f56a3df77dca < 177f25d1292c7e16e1199b39c85480f7f8815552 (affected), b2b6cadad699d44a8a5b2a60f3d960e00d6fb3b7 (affected), fe6c9b48ebc920ff21c10c50ab2729440c734254 (affected), 3.10.16 < 3.11 (affected), 3.11.5 < 3.12 (affected)
Linux Linux 3.12 (affected), 0 < 3.12 (unaffected), 4.19.324 <= 4.19.* (unaffected), 5.4.286 <= 5.4.* (unaffected), 5.10.230 <= 5.10.* (unaffected), 5.15.172 <= 5.15.* (unaffected), 6.1.117 <= 6.1.* (unaffected), 6.6.61 <= 6.6.* (unaffected), 6.11.8 <= 6.11.* (unaffected), 6.12 <= * (unaffected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
0.809%

Identity & Timeline

StatusPUBLISHED
Assigning Authoritykernel.org · Vendor · USA
Reserved2024-10-21T19:36:19
Published2024-11-19T01:30:51
Last Updated2026-05-23T15:55:02

LINK COPIED TO CLIPBOARD