In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.
History

Tue, 12 May 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens ruggedcom Rst2428p
Siemens scalance Xc316-8
Siemens scalance Xc319-4
Siemens scalance Xc324-4
Siemens scalance Xc324-4eec
Siemens scalance Xc332
Siemens scalance Xc416-8
Siemens scalance Xc419-4
Siemens scalance Xc424-4
Siemens scalance Xc432
Siemens scalance Xch328
Siemens scalance Xcm324
Siemens scalance Xcm328
Siemens scalance Xcm332
Siemens scalance Xr302-32
Siemens scalance Xr322-12
Siemens scalance Xr326-8
Siemens scalance Xr326-8eec
Siemens scalance Xr502-32
Siemens scalance Xr522-12
Siemens scalance Xr524-8c
Siemens scalance Xr524-8wg
Siemens scalance Xr526-8
Siemens scalance Xr526-8c
Siemens scalance Xr528-6m
Siemens scalance Xr552-12m
Siemens scalance Xrh334
Siemens scalance Xrm334
Siemens simatic S7-1500 Tm Mfp
Siemens simatic S7-1500 Tm Mfp Firmware
Siemens sinec Os
CPEs cpe:2.3:h:siemens:ruggedcom_rst2428p:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xc316-8:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xc319-4:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xc324-4:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xc324-4eec:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xc332:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xc416-8:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xc419-4:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xc424-4:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xc432:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xch328:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xcm324:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xcm328:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xcm332:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xr302-32:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xr322-12:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xr326-8:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xr326-8eec:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xr502-32:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xr522-12:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xr524-8c:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xr524-8wg:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xr526-8:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xr526-8c:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xr528-6m:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xr552-12m:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xrh334:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_xrm334:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-1500_tm_mfp:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_s7-1500_tm_mfp_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:sinec_os:*:*:*:*:*:*:*:*
Vendors & Products Siemens
Siemens ruggedcom Rst2428p
Siemens scalance Xc316-8
Siemens scalance Xc319-4
Siemens scalance Xc324-4
Siemens scalance Xc324-4eec
Siemens scalance Xc332
Siemens scalance Xc416-8
Siemens scalance Xc419-4
Siemens scalance Xc424-4
Siemens scalance Xc432
Siemens scalance Xch328
Siemens scalance Xcm324
Siemens scalance Xcm328
Siemens scalance Xcm332
Siemens scalance Xr302-32
Siemens scalance Xr322-12
Siemens scalance Xr326-8
Siemens scalance Xr326-8eec
Siemens scalance Xr502-32
Siemens scalance Xr522-12
Siemens scalance Xr524-8c
Siemens scalance Xr524-8wg
Siemens scalance Xr526-8
Siemens scalance Xr526-8c
Siemens scalance Xr528-6m
Siemens scalance Xr552-12m
Siemens scalance Xrh334
Siemens scalance Xrm334
Siemens simatic S7-1500 Tm Mfp
Siemens simatic S7-1500 Tm Mfp Firmware
Siemens sinec Os

Tue, 12 May 2026 13:30:00 +0000


Tue, 04 Nov 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Debian
Debian debian Linux
CPEs cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Vendors & Products Debian
Debian debian Linux

Mon, 03 Nov 2025 23:30:00 +0000

Type Values Removed Values Added
References

Mon, 03 Nov 2025 21:30:00 +0000

Type Values Removed Values Added
References

Tue, 21 Oct 2025 23:15:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google
Google android
References

Wed, 30 Jul 2025 02:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00247}

epss

{'score': 0.00219}


Fri, 04 Apr 2025 02:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.16::el9

Thu, 20 Mar 2025 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.13::el9
cpe:/a:redhat:openshift:4.14::el9

Fri, 14 Mar 2025 02:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.12::el8

Thu, 13 Mar 2025 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.15::el9

Thu, 13 Mar 2025 02:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.17::el9

Wed, 12 Mar 2025 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift
CPEs cpe:/a:redhat:enterprise_linux:9
cpe:/a:redhat:openshift:4.18::el9
cpe:/o:redhat:enterprise_linux:9
cpe:/o:redhat:rhel_aus:8.2
Vendors & Products Redhat openshift

Tue, 11 Mar 2025 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Els
Redhat rhel Extras Rt Els
CPEs cpe:/a:redhat:rhel_e4s:9.0
cpe:/a:redhat:rhel_e4s:9.0::nfv
cpe:/a:redhat:rhel_extras_rt_els:7
cpe:/a:redhat:rhel_tus:8.4::nfv
cpe:/o:redhat:rhel_aus:7.7
cpe:/o:redhat:rhel_aus:8.4
cpe:/o:redhat:rhel_e4s:8.4
cpe:/o:redhat:rhel_els:6
cpe:/o:redhat:rhel_els:7
cpe:/o:redhat:rhel_eus:8.8
cpe:/o:redhat:rhel_tus:8.4
Vendors & Products Redhat rhel Els
Redhat rhel Extras Rt Els

Mon, 10 Mar 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
Redhat rhel Aus
Redhat rhel E4s
Redhat rhel Eus
Redhat rhel Tus
CPEs cpe:/a:redhat:enterprise_linux:8::nfv
cpe:/a:redhat:rhel_eus:9.2
cpe:/a:redhat:rhel_eus:9.2::nfv
cpe:/a:redhat:rhel_eus:9.4
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:rhel_aus:8.6
cpe:/o:redhat:rhel_e4s:8.6
cpe:/o:redhat:rhel_tus:8.6
Vendors & Products Redhat
Redhat enterprise Linux
Redhat rhel Aus
Redhat rhel E4s
Redhat rhel Eus
Redhat rhel Tus

Sun, 09 Mar 2025 14:30:00 +0000


Sat, 08 Mar 2025 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665
Metrics threat_severity

Important

threat_severity

Moderate


Wed, 05 Mar 2025 14:45:00 +0000

Type Values Removed Values Added
References

Tue, 04 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2025-03-04'}


Tue, 04 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sun, 02 Mar 2025 06:30:00 +0000

Type Values Removed Values Added
Metrics threat_severity

Low

threat_severity

Important


Wed, 27 Nov 2024 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
Weaknesses CWE-908
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc6:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H'}

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Fri, 22 Nov 2024 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Low


Tue, 19 Nov 2024 01:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.
Title HID: core: zero-initialize the report buffer
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-05-23T15:55:02.106Z

Reserved: 2024-10-21T19:36:19.987Z

Link: CVE-2024-50302

cve-icon Vulnrichment

Updated: 2025-11-03T22:28:19.656Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-19T02:16:32.320

Modified: 2026-05-12T18:47:16.597

Link: CVE-2024-50302

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-11-19T00:00:00Z

Links: CVE-2024-50302 - Bugzilla

cve-icon OpenCVE Enrichment

No data.