Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5022 articles · 188920 vulns · 37/41 feeds (7d)
← Back to list
5.5
CVE-2024-50302KEVEXPLOITEDPATCHED
google · android

HID: core: zero-initialize the report buffer

Description

In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.

Affected Products

VendorProductVersions
googleandroid27ce405039bfe6d3f4143415c638f56a3df77dca, 27ce405039bfe6d3f4143415c638f56a3df77dca, 27ce405039bfe6d3f4143415c638f56a3df77dca, 27ce405039bfe6d3f4143415c638f56a3df77dca, 27ce405039bfe6d3f4143415c638f56a3df77dca, 27ce405039bfe6d3f4143415c638f56a3df77dca, 27ce405039bfe6d3f4143415c638f56a3df77dca, 27ce405039bfe6d3f4143415c638f56a3df77dca, b2b6cadad699d44a8a5b2a60f3d960e00d6fb3b7, fe6c9b48ebc920ff21c10c50ab2729440c734254, 3.12

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
amazonamazon linuxcert_advisory90%
canonicalubuntu linuxcert_advisory90%
debiandebian linuxcert_advisory90%
debiandebian_linuxcve_cpe95%
delldell poweredgecert_advisory90%

References

  • https://git.kernel.org/stable/c/e7ea60184e1e88a3c9e437b3265cbb6439aa7e26
  • https://git.kernel.org/stable/c/3f9e88f2672c4635960570ee9741778d4135ecf5
  • https://git.kernel.org/stable/c/d7dc68d82ab3fcfc3f65322465da3d7031d4ab46
  • https://git.kernel.org/stable/c/05ade5d4337867929e7ef664e7ac8e0c734f1aaf
  • https://git.kernel.org/stable/c/1884ab3d22536a5c14b17c78c2ce76d1734e8b0b
  • https://git.kernel.org/stable/c/9d9f5c75c0c7f31766ec27d90f7a6ac673193191
  • https://git.kernel.org/stable/c/492015e6249fbcd42138b49de3c588d826dd9648
  • https://git.kernel.org/stable/c/177f25d1292c7e16e1199b39c85480f7f8815552

Related News (3 articles)

Tier E
Hacker News6h ago
Cellebrite zero-day exploit used to target phone of Serbian student activist
→ No new info (linked only)
Tier D
SecurityWeek99d ago
Critical Remote Code Execution Vulnerability Patched in Android
→ No new info (linked only)
Tier B
BSI Advisories100d ago
[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen
→ No new info (linked only)
CVSS 3.15.5 MEDIUM
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
4.19.3245.4.2865.10.2305.15.1726.1.1176.6.616.11.8
PublishedNov 19, 2024
Last enriched132d ago
Trending Score119🔥
Source articles3
Independent3
Info Completeness11/14
Missing: epss, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-19157
CVE-2026-19157: Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentiall
Trending: 54
CRITICALCVE-2026-19149
CVE-2026-19149: Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perfor
Trending: 54
CRITICALCVE-2026-19170
CVE-2026-19170: Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially per
Trending: 54
HIGHCVE-2026-19177
CVE-2026-19177: Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who
Trending: 52
HIGHCVE-2026-19137
CVE-2026-19137: Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromise
Trending: 52

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Nov 19, 2024
Added to CISA KEV
Nov 19, 2024
Discovered by ZDM
Apr 1, 2026
Actively Exploited
May 12, 2026
Exploit Available
May 12, 2026
Patch Available
May 12, 2026