CVE-2024-58016

MEDIUM EPSS 8.5%
Published Feb 27, 20251y ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Feb 27, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: safesetid: check size of policy writes syzbot attempts to write a buffer with a large size to a sysfs entry with writes handled by handle_policy_update(), triggering a warning in kmalloc. Check the size specified for write buffers before allocating. [PM: subject tweak]

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
8.5% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 6

VendorProductVersionRange
linuxlinux_kernel*≥5.1  –  <5.10.235
linuxlinux_kernel*≥5.11  –  <5.15.179
linuxlinux_kernel*≥5.16  –  <6.1.129
linuxlinux_kernel*≥6.2  –  <6.6.78
linuxlinux_kernel*≥6.7  –  <6.12.14
linuxlinux_kernel*≥6.13  –  <6.13.3

References 10

  • cert-portal.siemens.com https://cert-portal.siemens.com/productcert/html/ssa-265688.html
  • git.kernel.org https://git.kernel.org/stable/c/36b385d0f2b4c0bf41d491e19075ecd990d2bf94
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/96fae5bd1589731592d30b3953a90a77ef3928a6
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/976284b94f2021df09829e37a367e19b84d9e5f3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a0dec65f88c8d9290dfa1d2ca1e897abe54c5881
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c71d35676d46090c891b6419f253fb92a1a9f4eb
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ecf6a4a558097920447a6fb84dfdb279e2ac749a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f09ff307c7299392f1c88f763299e24bc99811c7
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/36b385d0f2b4c0bf41d491e19075ecd990d2bf94
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/96fae5bd1589731592d30b3953a90a77ef3928a6
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/976284b94f2021df09829e37a367e19b84d9e5f3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a0dec65f88c8d9290dfa1d2ca1e897abe54c5881
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c71d35676d46090c891b6419f253fb92a1a9f4eb
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ecf6a4a558097920447a6fb84dfdb279e2ac749a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f09ff307c7299392f1c88f763299e24bc99811c7
    Patch