In the Linux kernel, the following vulnerability has been resolved: safesetid: check size of policy writes syzbot attempts to write a buffer with a large size to a sysfs entry with writes handled by handle_policy_update(), triggering a warning in kmalloc. Check the size specified for write buffers before allocating. [PM: subject tweak]
Update Linux/Linux to 976284b94f2021df09829e37a367e19b84d9e5f3; Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP to *; Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP to *; Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem to *; Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFP to * if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scansafesetid: check size of policy writes affects Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic), Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (generic). Severity is medium. In the Linux kernel, the following vulnerability has been resolved: safesetid: check size of policy writes syzbot attempts to write a buffer with a large size to a sysfs entry with writes handled by handle_policy_update(), triggering a warning in kmalloc. Check the size specified for write buffers before allocating. [PM: subject tweak]
AI coding agents often install or upgrade packages automatically in generic. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
In the Linux kernel, the following vulnerability has been resolved: safesetid: check size of policy writes syzbot attempts to write a buffer with a large size to a sysfs entry with writes handled by handle_policy_update(), triggering a warning in kmalloc. Check the size specified for write buffers before allocating. [PM: subject tweak]
Update Linux/Linux to 976284b94f2021df09829e37a367e19b84d9e5f3; Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP to *; Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP to *; Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem to *; Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFP to * if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scansafesetid: check size of policy writes affects Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic), Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (generic). Severity is medium. In the Linux kernel, the following vulnerability has been resolved: safesetid: check size of policy writes syzbot attempts to write a buffer with a large size to a sysfs entry with writes handled by handle_policy_update(), triggering a warning in kmalloc. Check the size specified for write buffers before allocating. [PM: subject tweak]
AI coding agents often install or upgrade packages automatically in generic. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
| Linux/Linuxgeneric | >=aeca4e2ca65c1aeacfbe520684e6421719d99417 <976284b94f2021df09829e37a367e19b84d9e5f3 || >=aeca4e2ca65c1aeacfbe520684e6421719d99417 <ecf6a4a558097920447a6fb84dfdb279e2ac749a || >=aeca4e2ca65c1aeacfbe520684e6421719d99417 <a0dec65f88c8d9290dfa1d2ca1e897abe54c5881 || >=aeca4e2ca65c1aeacfbe520684e6421719d99417 <96fae5bd1589731592d30b3953a90a77ef3928a6 || >=aeca4e2ca65c1aeacfbe520684e6421719d99417 <36b385d0f2b4c0bf41d491e19075ecd990d2bf94 || >=aeca4e2ca65c1aeacfbe520684e6421719d99417 <c71d35676d46090c891b6419f253fb92a1a9f4eb || >=aeca4e2ca65c1aeacfbe520684e6421719d99417 <f09ff307c7299392f1c88f763299e24bc99811c7 | 976284b94f2021df09829e37a367e19b84d9e5f3, ecf6a4a558097920447a6fb84dfdb279e2ac749a, a0dec65f88c8d9290dfa1d2ca1e897abe54c5881, 96fae5bd1589731592d30b3953a90a77ef3928a6, 36b385d0f2b4c0bf41d491e19075ecd990d2bf94, c71d35676d46090c891b6419f253fb92a1a9f4eb, f09ff307c7299392f1c88f763299e24bc99811c7 |
|---|---|---|
| Linux/Linuxgeneric | 5.1 | Not reported |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystemgeneric | >=0 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Linux/Linuxgeneric | >=aeca4e2ca65c1aeacfbe520684e6421719d99417 <976284b94f2021df09829e37a367e19b84d9e5f3 || >=aeca4e2ca65c1aeacfbe520684e6421719d99417 <ecf6a4a558097920447a6fb84dfdb279e2ac749a || >=aeca4e2ca65c1aeacfbe520684e6421719d99417 <a0dec65f88c8d9290dfa1d2ca1e897abe54c5881 || >=aeca4e2ca65c1aeacfbe520684e6421719d99417 <96fae5bd1589731592d30b3953a90a77ef3928a6 || >=aeca4e2ca65c1aeacfbe520684e6421719d99417 <36b385d0f2b4c0bf41d491e19075ecd990d2bf94 || >=aeca4e2ca65c1aeacfbe520684e6421719d99417 <c71d35676d46090c891b6419f253fb92a1a9f4eb || >=aeca4e2ca65c1aeacfbe520684e6421719d99417 <f09ff307c7299392f1c88f763299e24bc99811c7 | 976284b94f2021df09829e37a367e19b84d9e5f3, ecf6a4a558097920447a6fb84dfdb279e2ac749a, a0dec65f88c8d9290dfa1d2ca1e897abe54c5881, 96fae5bd1589731592d30b3953a90a77ef3928a6, 36b385d0f2b4c0bf41d491e19075ecd990d2bf94, c71d35676d46090c891b6419f253fb92a1a9f4eb, f09ff307c7299392f1c88f763299e24bc99811c7 |
|---|---|---|
| Linux/Linuxgeneric | 5.1 | Not reported |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystemgeneric | >=0 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard