CVE-2024-50302
Linux Kernel Use of Uninitialized Resource Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 25 March 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.81% probability · 55th percentile
- CISA KEV
- Listed 4 March 2025 · due 25 March 2025
- Weakness
- CWE-908
- Affected
- google/android · debian/debian linux · siemens/simatic s7-1500 tm mfp firmware · siemens/sinec os · linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://lore.kernel.org/linux-cve-announce/2024111908-CVE-2024-50302-f677@gregkh/ ; https://source.android.com/docs/security/bulletin/2025-03-01 ; https://nvd.nist.gov/vuln/detail/CVE-2024-50302
References
- https://git.kernel.org/stable/c/05ade5d4337867929e7ef664e7ac8e0c734f1aafPatch
- https://git.kernel.org/stable/c/177f25d1292c7e16e1199b39c85480f7f8815552Patch
- https://git.kernel.org/stable/c/1884ab3d22536a5c14b17c78c2ce76d1734e8b0bPatch
- https://git.kernel.org/stable/c/3f9e88f2672c4635960570ee9741778d4135ecf5Patch
- https://git.kernel.org/stable/c/492015e6249fbcd42138b49de3c588d826dd9648Patch
- https://git.kernel.org/stable/c/9d9f5c75c0c7f31766ec27d90f7a6ac673193191Patch
- https://git.kernel.org/stable/c/d7dc68d82ab3fcfc3f65322465da3d7031d4ab46Patch
- https://git.kernel.org/stable/c/e7ea60184e1e88a3c9e437b3265cbb6439aa7e26Patch
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.htmlMailing List
- https://lists.debian.org/debian-lts-announce/2025/03/msg00002.htmlMailing List
- https://cert-portal.siemens.com/productcert/html/ssa-265688.htmlThird Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-355557.htmlThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-50302US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.