Junglewise Threat Intelligence

CVE-2024-50302: Linux Kernel Use of Uninitialized Resource Vulnerability

CVE-2024-50302 · Severity: critical · CVSS 5.5 · Exploited in the wild · Published 2024-11-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Human Interface Device (HID) subsystem could allow a local attacker to access sensitive information. The issue stems from how the system handles data buffers for devices like keyboards and mice. An attacker could potentially use a specially crafted device report to leak fragments of kernel memory, which might contain sensitive system data.

Technical details

A use of uninitialized resource vulnerability (CWE-908) exists in the Linux kernel HID (Human Interface Device) core. The `hid_alloc_report_buf` function in `drivers/hid/hid-core.c` used `kmalloc` to allocate report buffers, which does not zero-initialize the memory. Because these buffers are used by various drivers to process device reports, an attacker with local access could potentially trigger a kernel memory leak by providing a specially-crafted report that reads from the uninitialized portions of the buffer. The fix replaces `kmalloc` with `kzalloc` to ensure the buffer is zero-initialized upon allocation. This vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog.

Affected products

  • Linux Linux Kernel 3.12 to 4.19.324, 4.20 to 5.4.286, 5.5 to 5.10.230, 5.11 to 5.15.172, 5.16 to 6.1.117, 6.2 to 6.6.61, 6.7 to 6.11.8, 6.12-rc1 to 6.12-rc5

Timeline

  • 2024-10-29: patched: Initial patch authored by Jiri Kosina
  • 2024-11-19: disclosed: CVE published
  • 2025-03-04: kev added: Added to CISA Known Exploited Vulnerabilities catalog

References

Related threats