CVE-2024-50302
Confirmed PUBLISHEDHID: core: zero-initialize the report buffer
Recommended Action
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
At a Glance
In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.
- CVE Published
- Nov 19, 2024
- Exploitation Reported
- Mar 04, 2025
- CVSS
- 5.5 Medium
- EPSS
- 0.8%
Affected Versions
26 version rows · page 1 of 2
| Vendor | Product | Version | Status |
|---|---|---|---|
| Siemens |
RUGGEDCOM RST2428P
|
0 to < * |
Unaffected |
| Siemens |
SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family
|
0 to < * |
Unaffected |
| Siemens |
SCALANCE XCM-/XRM-/XCH-/XRH-300 family
|
0 to < * |
Unaffected |
| Siemens |
SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
|
0 to < * |
Affected |
| Linux |
Linux
|
27ce405039bfe6d3f4143415c638f56a3df77dca to < e7ea60184e1e88a3c9e437b3265cbb6439aa7e26 |
Affected |
| Linux |
Linux
|
27ce405039bfe6d3f4143415c638f56a3df77dca to < 3f9e88f2672c4635960570ee9741778d4135ecf5 |
Affected |
| Linux |
Linux
|
27ce405039bfe6d3f4143415c638f56a3df77dca to < d7dc68d82ab3fcfc3f65322465da3d7031d4ab46 |
Affected |
| Linux |
Linux
|
27ce405039bfe6d3f4143415c638f56a3df77dca to < 05ade5d4337867929e7ef664e7ac8e0c734f1aaf |
Affected |
| Linux |
Linux
|
27ce405039bfe6d3f4143415c638f56a3df77dca to < 1884ab3d22536a5c14b17c78c2ce76d1734e8b0b |
Affected |
| Linux |
Linux
|
27ce405039bfe6d3f4143415c638f56a3df77dca to < 9d9f5c75c0c7f31766ec27d90f7a6ac673193191 |
Affected |
| Linux |
Linux
|
27ce405039bfe6d3f4143415c638f56a3df77dca to < 492015e6249fbcd42138b49de3c588d826dd9648 |
Affected |
| Linux |
Linux
|
27ce405039bfe6d3f4143415c638f56a3df77dca to < 177f25d1292c7e16e1199b39c85480f7f8815552 |
Affected |
| Linux |
Linux
|
b2b6cadad699d44a8a5b2a60f3d960e00d6fb3b7 |
Affected |
| Linux |
Linux
|
fe6c9b48ebc920ff21c10c50ab2729440c734254 |
Affected |
| Linux |
Linux
|
3.10.16 to < 3.11 |
Affected |
| Linux |
Linux
|
3.11.5 to < 3.12 |
Affected |
| Linux |
Linux
|
3.12 |
Affected |
| Linux |
Linux
|
0 to < 3.12 |
Unaffected |
| Linux |
Linux
|
4.19.324 to <= 4.19.* |
Unaffected |
| Linux |
Linux
|
5.4.286 to <= 5.4.* |
Unaffected |
| Linux |
Linux
|
5.10.230 to <= 5.10.* |
Unaffected |
| Linux |
Linux
|
5.15.172 to <= 5.15.* |
Unaffected |
| Linux |
Linux
|
6.1.117 to <= 6.1.* |
Unaffected |
| Linux |
Linux
|
6.6.61 to <= 6.6.* |
Unaffected |
| Linux |
Linux
|
6.11.8 to <= 6.11.* |
Unaffected |
CVE References
- git.kernel.org/stable/c/e7ea60184e1e88a3c9e437b3265cbb6439a... git.kernel.org · CVE Record https://git.kernel.org/stable/c/e7ea60184e1e88a3c9e437b3265cbb6439aa7e26
- git.kernel.org/stable/c/3f9e88f2672c4635960570ee9741778d413... git.kernel.org · CVE Record https://git.kernel.org/stable/c/3f9e88f2672c4635960570ee9741778d4135ecf5
- git.kernel.org/stable/c/d7dc68d82ab3fcfc3f65322465da3d7031d... git.kernel.org · CVE Record https://git.kernel.org/stable/c/d7dc68d82ab3fcfc3f65322465da3d7031d4ab46
- git.kernel.org/stable/c/05ade5d4337867929e7ef664e7ac8e0c734... git.kernel.org · CVE Record https://git.kernel.org/stable/c/05ade5d4337867929e7ef664e7ac8e0c734f1aaf
- git.kernel.org/stable/c/1884ab3d22536a5c14b17c78c2ce76d1734... git.kernel.org · CVE Record https://git.kernel.org/stable/c/1884ab3d22536a5c14b17c78c2ce76d1734e8b0b
Show 3 more references
- git.kernel.org/stable/c/9d9f5c75c0c7f31766ec27d90f7a6ac6731... git.kernel.org · CVE Record https://git.kernel.org/stable/c/9d9f5c75c0c7f31766ec27d90f7a6ac673193191
- git.kernel.org/stable/c/492015e6249fbcd42138b49de3c588d826d... git.kernel.org · CVE Record https://git.kernel.org/stable/c/492015e6249fbcd42138b49de3c588d826dd9648
- git.kernel.org/stable/c/177f25d1292c7e16e1199b39c85480f7f88... git.kernel.org · CVE Record https://git.kernel.org/stable/c/177f25d1292c7e16e1199b39c85480f7f8815552
Recommended Actions
- Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
- Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
- Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
Per-source evidence links for KEV attestations are available through the KEVIntel Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CISA First | 2025-03-04 00:00 UTC |
| CVE | 2026-06-05 09:12 UTC |
No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Virtual Patch
Compensating WAF rules to help reduce exposure to this CVE. Rule content and deployable vendor exports are available with KEVIntel Enterprise.
KEVIntel does not currently have a virtual patch for this CVE. When available, KEVIntel virtual patches ship as deployable ModSecurity, Cloudflare, and AWS WAF rules.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEVIntel Enterprise users.
CVSS Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitation Status
Exploited in the wild
Recorded 2025-03-04 00:00:00 UTC · CISA
Weaknesses (CWE)
-
Use of Uninitialized Resource
Scanner Integrations
| Scanner | Reference | Detected |
|---|---|---|
| Nessus | https://www.tenable.com/plugins/nessus/237432 | Jun 02, 2025 |
Timeline
Key exploitation, disclosure, scanner coverage, and KEV attestation events for this CVE.
-
09:12 UTC about 2 months ago09:12 UTC · about 2 months ago
KEV confirmed by CVE
Exploitation attested by an external source
-
09:25 UTC about 1 year ago09:25 UTC · about 1 year ago
Nessus plugin available
Scanner coverage available
-
00:00 UTC over 1 year ago00:00 UTC · over 1 year ago
Added to CISA KEV
Listed in the CISA Known Exploited Vulnerabilities catalog
-
01:30 UTC over 1 year ago01:30 UTC · over 1 year ago
CVE published
Vulnerability disclosed publicly
-
19:36 UTC over 1 year ago19:36 UTC · over 1 year ago
CVE ID reserved
Identifier reserved by the CNA
Automate This Intelligence with the Pro API
Confidence scoring, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
Pro API Example
GET /api/v2/pro/kevs/CVE-2024-50302
{
"cve_id": "CVE-2024-50302",
"title": "HID: core: zero-initialize the report buffer",
"affected_vendor": "Linux",
"affected_product": "Linux",
"affected_versions": [
{ "vendor": "...", "product": "...", "status": "affected", "display_label": "..." }
],
"confidence": "Confirmed",
"cvss_score": 5.5,
"epss_score": 0.00809,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "...": "Pro API fields" },
"proof_of_concepts": [ "..." ],
"scanner_integrations": [ "..." ]
}