CISA KEV 정보
| 취약점명 | Linux Kernel Use of Uninitialized Resource Vulnerability |
|---|---|
| 설명 | The Linux kernel contains a use of uninitialized resource vulnerability that allows an attacker to leak kernel memory via a specially crafted HID report. |
| 조치사항 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
| 랜섬웨어 캠페인 악용 | Unknown |
| CWE | CWE-908 |
| 등록일 (KEV) | 2025-03-04 |
| 조치 기한 | 2025-03-25 |
| 추가 참고 | This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://lore.kernel.org/linux-cve-announce/2024111908-CVE-2024-50302-f677@gregkh/ ; https://source.android.com/docs/security/bulletin/2025-03-01 ; https://nvd.nist.gov/vuln/detail/CVE-2024-50302 |
NVD 상세 정보
CVSS v3.1: 5.5 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N설명: In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.
CWE: CWE-908 | CWE-908
참조
- https://git.kernel.org/stable/c/05ade5d4337867929e7ef664e7ac8e0c734f1aaf [Patch]
- https://git.kernel.org/stable/c/177f25d1292c7e16e1199b39c85480f7f8815552 [Patch]
- https://git.kernel.org/stable/c/1884ab3d22536a5c14b17c78c2ce76d1734e8b0b [Patch]
- https://git.kernel.org/stable/c/3f9e88f2672c4635960570ee9741778d4135ecf5 [Patch]
- https://git.kernel.org/stable/c/492015e6249fbcd42138b49de3c588d826dd9648 [Patch]
- https://git.kernel.org/stable/c/9d9f5c75c0c7f31766ec27d90f7a6ac673193191 [Patch]
- https://git.kernel.org/stable/c/d7dc68d82ab3fcfc3f65322465da3d7031d4ab46 [Patch]
- https://git.kernel.org/stable/c/e7ea60184e1e88a3c9e437b3265cbb6439aa7e26 [Patch]
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html [Mailing List]
- https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html [Mailing List]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-50302 [US Government Resource]
This product uses the NVD API but is not endorsed or certified by the NVD.