Lyrie
Actively Exploited
CVSS 5.5ACTIVELY EXPLOITED4 sources verified·1 min read
By Lyrie Threat Intelligence·5/12/2026

MEDIUM: CVE-2024-50302 actively exploited — google android

CVE: CVE-2024-50302

CVSS: 5.5 (3.1) — CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: MEDIUM

Status: ✅ Confirmed exploited in the wild (CISA KEV)

Affected

  • google android
  • debian debian linux
  • linux linux kernel

Summary

In the Linux kernel, the following vulnerability has been resolved:

HID: core: zero-initialize the report buffer

Since the report buffer is used by all kinds of drivers in various ways, let's

zero-initialize it during allocation to make sure that it can't be ever used

to leak kernel memory via specially-crafted report.

Verified Sources

References

  • https://git.kernel.org/stable/c/05ade5d4337867929e7ef664e7ac8e0c734f1aaf
  • https://git.kernel.org/stable/c/177f25d1292c7e16e1199b39c85480f7f8815552
  • https://git.kernel.org/stable/c/1884ab3d22536a5c14b17c78c2ce76d1734e8b0b
  • https://git.kernel.org/stable/c/3f9e88f2672c4635960570ee9741778d4135ecf5
  • https://git.kernel.org/stable/c/492015e6249fbcd42138b49de3c588d826dd9648
  • https://git.kernel.org/stable/c/9d9f5c75c0c7f31766ec27d90f7a6ac673193191
  • https://git.kernel.org/stable/c/d7dc68d82ab3fcfc3f65322465da3d7031d4ab46
  • https://git.kernel.org/stable/c/e7ea60184e1e88a3c9e437b3265cbb6439aa7e26
  • https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
  • https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html

_Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation._

Lyrie Verdict

Lyrie's autonomous detection layer catches active exploitation primitives at machine speed — closing the gap between disclosure and weaponization that traditional defense simply can't cover.

Validated sources

  1. [1]NVD
  2. [2]GitHub Advisory
  3. [3]MITRE
  4. [4]CISA KEV