{"schema_version":"1.9.0","id":"CVE-2024-58016","published":"2025-02-27T02:12:08.547Z","modified":"2026-08-12T03:51:16.536759615Z","related":["USN-7521-2"],"summary":"safesetid: check size of policy writes","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nsafesetid: check size of policy writes\n\nsyzbot attempts to write a buffer with a large size to a sysfs entry\nwith writes handled by handle_policy_update(), triggering a warning\nin kmalloc.\n\nCheck the size specified for write buffers before allocating.\n\n[PM: subject tweak]","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"aeca4e2ca65c1aeacfbe520684e6421719d99417"},{"fixed":"976284b94f2021df09829e37a367e19b84d9e5f3"},{"fixed":"ecf6a4a558097920447a6fb84dfdb279e2ac749a"},{"fixed":"a0dec65f88c8d9290dfa1d2ca1e897abe54c5881"},{"fixed":"96fae5bd1589731592d30b3953a90a77ef3928a6"},{"fixed":"36b385d0f2b4c0bf41d491e19075ecd990d2bf94"},{"fixed":"c71d35676d46090c891b6419f253fb92a1a9f4eb"},{"fixed":"f09ff307c7299392f1c88f763299e24bc99811c7"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58016.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.1.0"},{"fixed":"5.10.235"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.179"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.129"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.78"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.14"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.13.3"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58016.json"}}],"references":[{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-019113.html"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-265688.html"},{"type":"WEB","url":"https://git.kernel.org/stable/c/36b385d0f2b4c0bf41d491e19075ecd990d2bf94"},{"type":"WEB","url":"https://git.kernel.org/stable/c/96fae5bd1589731592d30b3953a90a77ef3928a6"},{"type":"WEB","url":"https://git.kernel.org/stable/c/976284b94f2021df09829e37a367e19b84d9e5f3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a0dec65f88c8d9290dfa1d2ca1e897abe54c5881"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c71d35676d46090c891b6419f253fb92a1a9f4eb"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ecf6a4a558097920447a6fb84dfdb279e2ac749a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f09ff307c7299392f1c88f763299e24bc99811c7"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/58xxx/CVE-2024-58016.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-58016"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/58xxx/CVE-2024-58016.json"}}