CVE-2024-58085: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: tomoyo: don't emit warning in tomoyo_write_control() syzbot is reporting too large allocation warning at tomoyo_write_control(), for one can write a very very long line without new line character. To fix this warning, I use __GFP_NOWARN rather than checking for KMALLOC_MAX_SIZE, for practically a valid line should be always shorter than 32KB where the "too small to fail" memory-allocation rule applies. One might try to write a valid line that is longer than 32KB, but such request will likely fail with -ENOMEM. Therefore, I feel that separately returning -EINVAL when a line is longer than KMALLOC_MAX_SIZE is redundant. There is no need to distinguish over-32KB and over-KMALLOC_MAX_SIZE.

Affected products

  • Linux Linux Kernel: before 5.4.291 (fixed in 5.4.291); from 5.5, before 5.10.235 (fixed in 5.10.235); from 5.11, before 5.15.179 (fixed in 5.15.179); from 5.16, before 6.1.129 (fixed in 6.1.129); from 6.2, before 6.6.78 (fixed in 6.6.78); from 6.7, before 6.12.14 (fixed in 6.12.14); …

Published 2025-03-06. Last modified 2026-06-17.