CVE-2024-58058

Source
https://cve.org/CVERecord?id=CVE-2024-58058
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-58058.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-58058
Downstream
Related
Published
2025-03-06T15:54:01.033Z
Modified
2026-05-07T04:17:17.943177Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
ubifs: skip dumping tnc tree when zroot is null
Details

In the Linux kernel, the following vulnerability has been resolved:

ubifs: skip dumping tnc tree when zroot is null

Clearing slab cache will free all znode in memory and make c->zroot.znode = NULL, then dumping tnc tree will access c->zroot.znode which cause null pointer dereference.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/58xxx/CVE-2024-58058.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1e51764a3c2ac05a23a22b2a95ddee4d9bffb16d
Fixed
428aff8f7cfb0d9a8854477648022cef96bcab28
Fixed
6211c11fc20424bbc6d79c835c7c212b553ae898
Fixed
1787cd67bb94b106555ffe64f887f6aa24b47010
Fixed
e01b55f261ccc96e347eba4931e4429d080d879d
Fixed
40e25a3c0063935763717877bb2a814c081509ff
Fixed
77e5266e3d3faa6bdcf20d9c68a8972f6aa06522
Fixed
2a987950df825d0144370e700dc5fb337684ffba
Fixed
bdb0ca39e0acccf6771db49c3f94ed787d05f2d7

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-58058.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.27
Fixed
5.4.291
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.235
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.179
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.129
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.76
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.13
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.13.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-58058.json"