Zero-day vulnerability in Google Android

Memory leak
CVE-2024-50302

Vulnerability details

Advisory: SB2025030358 - Multiple vulnerabilities in Google Android

Vulnerable component: Google Android

CVE-ID: CVE-2024-50302

CVSSv3 score: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:H/RL:O/RC:C

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

Description:

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the hid_alloc_report_buf() function in drivers/hid/hid-core.c. A local user can perform a denial of service (DoS) attack.

Note, the vulnerability is being actively exploited in the wild against Android devices.