CVE-2024-50302
In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.
- Affected products
- Alt Linux, Almalinux, Astra Linux, Centos, Debian, Linuxmint, Linux Kernel, Red Hat
- Google Android
- All versions
- CVSS 3.1
- 5.5 MEDIUM
- EPSS
- 0.8% (54th percentile)
- Weakness
- CWE-908
- NVD status
- Analyzed
- Published
- 2024-11-19
CVE-2024-50302 at NVD
1 known exploit for CVE-2024-50302
Proof-of-concept code and exploit modules indexed by Sploitus