CVE-2024-50302: Linux Kernel Use of Uninitialized Resource Vulnerability

Medium severity, CVSS 5.5. Actively exploited: in CISA KEV since 2025-03-04. EPSS: 0.8% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.

Affected products

  • Debian Debian Linux: version 11.0 only
  • Google Android: affected versions not specified
  • Linux Linux Kernel: from 3.12, before 4.19.324 (fixed in 4.19.324); from 4.20, before 5.4.286 (fixed in 5.4.286); from 5.5, before 5.10.230 (fixed in 5.10.230); from 5.11, before 5.15.172 (fixed in 5.15.172); from 5.16, before 6.1.117 (fixed in 6.1.117); from 6.2, before 6.6.61 (fixed in 6.6.61); …
  • Siemens SIMATIC s7-1500 TM Mfp Firmware: affected versions not specified
  • Siemens Sinec OS: before 3.2 (fixed in 3.2)

Published 2024-11-19. Last modified 2026-06-17.