CVE-2024-50302
בינונית 5.5 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Linux Kernel Use of Uninitialized Resource Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.
מדדים
- CVSS 3.1
-
5.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-26/7/2026
- CWE
- CWE-908
מוצרים מושפעים
google: android; debian: debian linux; siemens: simatic s7-1500 tm mfp firmware; siemens: simatic s7-1500 tm mfp; siemens: sinec os; siemens: ruggedcom rst2428p; siemens: scalance xc316-8; siemens: scalance xc319-4; siemens: scalance xc324-4; siemens: scalance xc324-4eec; siemens: scalance xc332; siemens: scalance xc416-8; siemens: scalance xc419-4; siemens: scalance xc424-4; siemens: scalance xc432
קישורים
- https://git.kernel.org/stable/c/05ade5d4337867929e7ef664e7ac8e0c734f1aaf Patch
- https://git.kernel.org/stable/c/177f25d1292c7e16e1199b39c85480f7f8815552 Patch
- https://git.kernel.org/stable/c/1884ab3d22536a5c14b17c78c2ce76d1734e8b0b Patch
- https://git.kernel.org/stable/c/3f9e88f2672c4635960570ee9741778d4135ecf5 Patch
- https://git.kernel.org/stable/c/492015e6249fbcd42138b49de3c588d826dd9648 Patch
- https://git.kernel.org/stable/c/9d9f5c75c0c7f31766ec27d90f7a6ac673193191 Patch
- https://git.kernel.org/stable/c/d7dc68d82ab3fcfc3f65322465da3d7031d4ab46 Patch
- https://git.kernel.org/stable/c/e7ea60184e1e88a3c9e437b3265cbb6439aa7e26 Patch
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html Mailing List
- https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html Mailing List