Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-58005

17
FAUCET Score

CVE-2024-58005 addresses a vulnerability in the Linux kernel's TPM eventlog/ACPI component, specifically affecting the 'linux_kernel' product. The issue stems from an incorrect memory allocation call (devm_kmalloc instead of kvmalloc and devm_add_action) that could lead to a system crash due to a 16 MiB buffer overflow when processing ACPI log events. Rated 5.5 MEDIUM (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H), this local vulnerability requires low privileges and complexity to trigger, potentially causing a denial of service. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.16, < 6.6.78CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.7, < 6.12.14CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.13, < 6.13.3CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 65th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.182.1-1 on CBL Mariner 2.0
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.179.1-1 on CBL Mariner 2.0Fixed in: 5.15.179.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.78.1-3 on Azure Linux 3.0Fixed in: 6.6.78.1-3
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.64.2-9 on Azure Linux 3.0Fixed in: 6.6.78.1-3
microsoftpatch availablevia msrc
Product: 17103-16823Fixed in: 5.15.179.1-1
microsoftpatch availablevia msrc
Product: 17471-17084Fixed in: 6.6.78.1-3
microsoftpatch availablevia msrc
Product: 17501-17084Fixed in: 6.6.78.1-3
microsoftpatch availablevia msrc
Product: 19682-17086
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-570.16.1.el9_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel-0:6.12.0-124.8.1.el10_1
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (2)

redhatCVE-2024-58005Moderate

kernel: tpm: Change to kvalloc() in eventlog/acpi.c

Feb 27, 2025
microsoft2025-Feb/CVE-2024-58005Moderate

tpm: Change to kvalloc() in eventlog/acpi.c

Feb 11, 2025

References

cert-portal.siemens.com / productcert/html/ssa-082556.html
cert-portal.siemens.com / productcert/html/ssa-265688.html
cert-portal.siemens.com / productcert/html/ssa-503939.html
git.kernel.org / stable/c/0621d2599d6e02d05c85d6bbd58eaea2f15b3503
git.kernel.org / stable/c/422d7f4e8d817be467986589c7968d3ea402f7da
Patch
git.kernel.org / stable/c/4c8bfe643bbd00b04ee8f9545ef33bf6a68c38db
Patch
git.kernel.org / stable/c/50365a6304a57266e8f4d3078060743c3b7a1e0d
Patch
git.kernel.org / stable/c/77779d1258a287f2c5c2c6aeae203e0996209c77
git.kernel.org / stable/c/a3a860bc0fd6c07332e4911cf9a238d20de90173
Patch
git.kernel.org / stable/c/a676c0401de59548a5bc1b7aaf98f556ae8ea6db
lists.debian.org / debian-lts-announce/2025/05/msg00030.html
lists.debian.org / debian-lts-announce/2025/05/msg00045.html