CVE-2024-50302

Source
https://cve.org/CVERecord?id=CVE-2024-50302
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-50302.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-50302
Aliases
Downstream
Related
Published
2024-11-19T01:30:51.300Z
Modified
2026-03-11T07:48:58.487693Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
HID: core: zero-initialize the report buffer
Details

In the Linux kernel, the following vulnerability has been resolved:

HID: core: zero-initialize the report buffer

Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/50xxx/CVE-2024-50302.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
27ce405039bfe6d3f4143415c638f56a3df77dca
Fixed
e7ea60184e1e88a3c9e437b3265cbb6439aa7e26
Fixed
3f9e88f2672c4635960570ee9741778d4135ecf5
Fixed
d7dc68d82ab3fcfc3f65322465da3d7031d4ab46
Fixed
05ade5d4337867929e7ef664e7ac8e0c734f1aaf
Fixed
1884ab3d22536a5c14b17c78c2ce76d1734e8b0b
Fixed
9d9f5c75c0c7f31766ec27d90f7a6ac673193191
Fixed
492015e6249fbcd42138b49de3c588d826dd9648
Fixed
177f25d1292c7e16e1199b39c85480f7f8815552
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
b2b6cadad699d44a8a5b2a60f3d960e00d6fb3b7
Last affected
fe6c9b48ebc920ff21c10c50ab2729440c734254

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-50302.json"