Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4996 articles · 189019 vulns · 37/41 feeds (7d)
← Back to list
5.5
CVE-2024-50302KEVEXPLOITEDPATCHED
google · android

HID: core: zero-initialize the report buffer

Description

In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.

Affected Products

VendorProductVersions
googleandroid27ce405039bfe6d3f4143415c638f56a3df77dca, 27ce405039bfe6d3f4143415c638f56a3df77dca, 27ce405039bfe6d3f4143415c638f56a3df77dca, 27ce405039bfe6d3f4143415c638f56a3df77dca, 27ce405039bfe6d3f4143415c638f56a3df77dca, 27ce405039bfe6d3f4143415c638f56a3df77dca, 27ce405039bfe6d3f4143415c638f56a3df77dca, 27ce405039bfe6d3f4143415c638f56a3df77dca, b2b6cadad699d44a8a5b2a60f3d960e00d6fb3b7, fe6c9b48ebc920ff21c10c50ab2729440c734254, 3.12

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
amazonamazon linuxcert_advisory90%
canonicalubuntu linuxcert_advisory90%
debiandebian linuxcert_advisory90%
debiandebian_linuxcve_cpe95%
delldell poweredgecert_advisory90%

References

  • https://git.kernel.org/stable/c/e7ea60184e1e88a3c9e437b3265cbb6439aa7e26
  • https://git.kernel.org/stable/c/3f9e88f2672c4635960570ee9741778d4135ecf5
  • https://git.kernel.org/stable/c/d7dc68d82ab3fcfc3f65322465da3d7031d4ab46
  • https://git.kernel.org/stable/c/05ade5d4337867929e7ef664e7ac8e0c734f1aaf
  • https://git.kernel.org/stable/c/1884ab3d22536a5c14b17c78c2ce76d1734e8b0b
  • https://git.kernel.org/stable/c/9d9f5c75c0c7f31766ec27d90f7a6ac673193191
  • https://git.kernel.org/stable/c/492015e6249fbcd42138b49de3c588d826dd9648
  • https://git.kernel.org/stable/c/177f25d1292c7e16e1199b39c85480f7f8815552

Related News (3 articles)

Tier E
Hacker News9h ago
Cellebrite zero-day exploit used to target phone of Serbian student activist
→ No new info (linked only)
Tier D
SecurityWeek99d ago
Critical Remote Code Execution Vulnerability Patched in Android
→ No new info (linked only)
Tier B
BSI Advisories100d ago
[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen
→ No new info (linked only)
CVSS 3.15.5 MEDIUM
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
4.19.3245.4.2865.10.2305.15.1726.1.1176.6.616.11.8
PublishedNov 19, 2024
Last enriched133d ago
Trending Score117🔥
Source articles3
Independent3
Info Completeness11/14
Missing: epss, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-19157
CVE-2026-19157: Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentiall
Trending: 54
CRITICALCVE-2026-19149
CVE-2026-19149: Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perfor
Trending: 54
CRITICALCVE-2026-19170
CVE-2026-19170: Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially per
Trending: 54
CRITICALCVE-2026-19175
CVE-2026-19175: Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a s
Trending: 51
CRITICALCVE-2026-19166
CVE-2026-19166: Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially p
Trending: 51

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Nov 19, 2024
Added to CISA KEV
Nov 19, 2024
Discovered by ZDM
Apr 1, 2026
Actively Exploited
May 12, 2026
Exploit Available
May 12, 2026
Patch Available
May 12, 2026