MEDIUM · 5.5

CVE-2024-50302

In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-i...

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
GoogleAndroid-
DebianDebian Linux11.0
SiemensSimatic S7-1500 Tm Mfp Firmware-
SiemensSimatic S7-1500 Tm Mfp-
SiemensSinec Os< 3.2
SiemensRuggedcom Rst2428P-
SiemensScalance Xc316-8-
SiemensScalance Xc319-4-
SiemensScalance Xc324-4-
SiemensScalance Xc324-4Eec-
SiemensScalance Xc332-
SiemensScalance Xc416-8-
SiemensScalance Xc419-4-
SiemensScalance Xc424-4-
SiemensScalance Xc432-
SiemensScalance Xch328-
SiemensScalance Xcm324-
SiemensScalance Xcm328-
SiemensScalance Xcm332-
SiemensScalance Xr302-32-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-50302?

CVE-2024-50302 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-i...

How severe is CVE-2024-50302?

CVE-2024-50302 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-50302?

Check the references section above for vendor advisories and patch information. Affected products include: Google Android, Debian Debian Linux, Siemens Simatic S7-1500 Tm Mfp Firmware, Siemens Simatic S7-1500 Tm Mfp, Siemens Sinec Os.