CVE-2024-58016

Source
https://cve.org/CVERecord?id=CVE-2024-58016
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-58016.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-58016
Downstream
Related
Published
2025-02-27T02:12:08.547Z
Modified
2026-05-28T03:54:57.329564034Z
Summary
safesetid: check size of policy writes
Details

In the Linux kernel, the following vulnerability has been resolved:

safesetid: check size of policy writes

syzbot attempts to write a buffer with a large size to a sysfs entry with writes handled by handlepolicyupdate(), triggering a warning in kmalloc.

Check the size specified for write buffers before allocating.

[PM: subject tweak]

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/58xxx/CVE-2024-58016.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
aeca4e2ca65c1aeacfbe520684e6421719d99417
Fixed
976284b94f2021df09829e37a367e19b84d9e5f3
Fixed
ecf6a4a558097920447a6fb84dfdb279e2ac749a
Fixed
a0dec65f88c8d9290dfa1d2ca1e897abe54c5881
Fixed
96fae5bd1589731592d30b3953a90a77ef3928a6
Fixed
36b385d0f2b4c0bf41d491e19075ecd990d2bf94
Fixed
c71d35676d46090c891b6419f253fb92a1a9f4eb
Fixed
f09ff307c7299392f1c88f763299e24bc99811c7

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-58016.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.1.0
Fixed
5.10.235
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.179
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.129
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.78
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.14
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.13.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-58016.json"