← Back to CVE intelligence
CVE intelligenceCISA KEV

CVE-2024-50302

Linux Kernel Use of Uninitialized Resource Vulnerability

Published Nov 19, 2024Sources checked Oct 5, 2026
5.5MEDIUMCVSS out of 10
What this means

Actively exploited

CISA lists CVE-2024-50302 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Linux Kernel.

  • Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
What to do next

Remediation and response

Microsoft Security Response Center guidance

Vendor revision: Aug 12, 2026

CBL-Mariner Releases

Vendor-listed releases

  • 5.15.173.1-1
  • 6.6.64.2-1
CISA KEVListedObserved exploitation
EPSS0.8%Estimated 30-day exploitation probability
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2024-50302?

In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.

Source: NVD

CISA says:Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.CISA catalog due date Mar 25, 2025