Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-50302

58
FAUCET Score

CVE-2024-50302 is a kernel memory information leak vulnerability in the Linux kernel, specifically within the Human Interface Device (HID) core. It affects various Linux-based systems, including Debian and Android, due to improper initialization of the report buffer. This flaw allows a local attacker to potentially disclose sensitive kernel memory via specially crafted reports. Rated with a CVSS score of 5.5 (Medium), this vulnerability has a low attack complexity and requires local access, but can lead to high confidentiality impacts. The EPSS score is low, yet the FAUCET Risk Score is high at 98/100, indicating significant concern. Critically, CVE-2024-50302 is actively exploited in the wild, as confirmed by its inclusion in the KEV catalog and multiple media reports linking it to zero-day exploits used by state-sponsored actors. Despite active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available. The vulnerability has garnered significant community discussion, indicating high awareness among security researchers.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
11.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:siemens:simatic_s7-1500_tm_mfp_firmware:-:*:*:*:*:*:*:*
< 3.2CPE matchmatch criteria
cpe:2.3:o:siemens:sinec_os:*:*:*:*:*:*:*:*
>= 3.12, < 4.19.324CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.81%
Probability of exploitation in next 30 days
EPSS Percentile
53.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Mar 4, 2025
This CVE's current EPSS score of 0.0081 is in the 96th percentile among its peer group of 15,938 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (50)

autodeskpatch availablevia llm_extracted
View patch
freepbxpatch availablevia llm_extracted
View patch
honeywellpatch availablevia llm_extracted
View patch
linuxpatch availablevia osv
Product: KernelFixed in: 5.15.172
linuxpatch availablevia osv
Product: KernelFixed in: 6.1.117
linuxpatch availablevia osv
Product: KernelFixed in: 6.6.61
linuxpatch availablevia osv
Product: KernelFixed in: 6.11.8
linuxpatch availablevia osv
Product: KernelFixed in: 4.19.324
linuxpatch availablevia osv
Product: KernelFixed in: 5.10.230
linuxpatch availablevia osv
Product: KernelFixed in: 5.4.286
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.57.1-7 on Azure Linux 3.0Fixed in: 6.6.64.2-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 5.15.173.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 5.15.173.1-1
microsoftpatch availablevia msrc
Product: 17123-16823Fixed in: 5.15.173.1-1
microsoftpatch availablevia msrc
Product: 19672-17086Fixed in: 5.15.173.1-1
microsoftpatch availablevia msrc
Product: 17156-17086Fixed in: 5.15.173.1-1
microsoftpatch availablevia msrc
Product: 17489-17084Fixed in: 6.6.64.2-1
microsoftpatch availablevia msrc
Product: 17088-17084Fixed in: 6.6.64.2-1
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.173.1-1 on CBL Mariner 2.0Fixed in: 5.15.173.1-1
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.167.1-2 on CBL Mariner 2.0Fixed in: 5.15.173.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.64.2-1 on Azure Linux 3.0Fixed in: 6.6.64.2-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: kernel-0:4.18.0-372.141.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-503.31.1.el9_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: kernel-0:5.14.0-70.125.1.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: kernel-rt-0:5.14.0-70.125.1.rt21.197.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: kernel-0:5.14.0-284.108.1.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: kernel-rt-0:5.14.0-284.108.1.rt14.393.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: kernel-0:5.14.0-427.59.1.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.12Fixed in: rhcos-412.86.202503052321-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.13Fixed in: rhcos-413.92.202503112237-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.14Fixed in: rhcos-414.92.202503100617-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: rhcos-415.92.202503060749-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.16Fixed in: rhcos-416.94.202503252048-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.17Fixed in: rhcos-417.94.202503060903-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.18Fixed in: rhcos-418.94.202503061016-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: kernel-rt-0:3.10.0-1160.133.1.rt56.1285.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.7 Advanced Update SupportFixed in: kernel-0:3.10.0-1062.93.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: kernel-0:4.18.0-477.93.1.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONFixed in: kernel-0:2.6.32-754.56.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: kernel-0:3.10.0-1160.133.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-553.44.1.rt7.385.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.44.1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: kernel-0:4.18.0-193.146.1.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: kernel-0:4.18.0-305.151.1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: kernel-rt-0:4.18.0-305.151.1.rt7.228.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: kernel-0:4.18.0-305.151.1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: kernel-0:4.18.0-305.151.1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: kernel-0:4.18.0-372.141.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: kernel-0:4.18.0-372.141.1.el8_6
View patch
junipervendor investigatingvia vendor_rss
View patch

Vendor Advisories (8)

juniperjuniper:ka0Dp000000v7EeIAILOW

2026-01 Security Bulletin: Junos OS Evolved: A Linux kernel vulnerability in the HID driver allows an attacker to read information from the HID Report buffer (CVE-2024-50302)

Jan 14, 2026
freepbxllm-freepbx-e54908c7967265f6CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
honeywellllm-honeywell-c82b5cfda9df97a3CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
autodeskllm-autodesk-c365b674a2ff5a3aCRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
microsoft2024-Dec/CVE-2024-50302

CVE-2024-50302

Dec 10, 2024
linuxCVE-2024-50302MEDIUM

HID: core: zero-initialize the report buffer

Nov 19, 2024
redhatCVE-2024-50302Moderate

kernel: HID: core: zero-initialize the report buffer

Nov 19, 2024
microsoft2024-Nov/CVE-2024-50302Moderate

HID: core: zero-initialize the report buffer

Nov 12, 2024

References

cert-portal.siemens.com / productcert/html/ssa-265688.html
Third Party Advisory
cert-portal.siemens.com / productcert/html/ssa-355557.html
Third Party Advisory
cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
git.kernel.org / stable/c/05ade5d4337867929e7ef664e7ac8e0c734f1aaf
Patch
git.kernel.org / stable/c/177f25d1292c7e16e1199b39c85480f7f8815552
Patch
git.kernel.org / stable/c/1884ab3d22536a5c14b17c78c2ce76d1734e8b0b
Patch
git.kernel.org / stable/c/3f9e88f2672c4635960570ee9741778d4135ecf5
Patch
git.kernel.org / stable/c/492015e6249fbcd42138b49de3c588d826dd9648
Patch
git.kernel.org / stable/c/9d9f5c75c0c7f31766ec27d90f7a6ac673193191
Patch
git.kernel.org / stable/c/d7dc68d82ab3fcfc3f65322465da3d7031d4ab46
Patch
git.kernel.org / stable/c/e7ea60184e1e88a3c9e437b3265cbb6439aa7e26
Patch
lists.debian.org / debian-lts-announce/2025/01/msg00001.html
Mailing List
lists.debian.org / debian-lts-announce/2025/03/msg00002.html
Mailing List