← לוח פגיעויות

CVE-2024-50302

בינונית 5.5 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Linux Kernel Use of Uninitialized Resource Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.

מדדים

CVSS 3.1
5.5 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS — סבירות ניצול
1% (אחוזון 100) נכון ל-26/7/2026
CWE
CWE-908

מוצרים מושפעים

google: android; debian: debian linux; siemens: simatic s7-1500 tm mfp firmware; siemens: simatic s7-1500 tm mfp; siemens: sinec os; siemens: ruggedcom rst2428p; siemens: scalance xc316-8; siemens: scalance xc319-4; siemens: scalance xc324-4; siemens: scalance xc324-4eec; siemens: scalance xc332; siemens: scalance xc416-8; siemens: scalance xc419-4; siemens: scalance xc424-4; siemens: scalance xc432

קישורים