CVE-2024-41085: cxl/mem: Fix no cxl_nvd during pmem region auto-assembling

Published Jul 29, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

cxl/mem: Fix no cxlnvd during pmem region auto-assembling

When CXL subsystem is auto-assembling a pmem region during cxl endpoint port probing, always hit below calltrace.

BUG: kernel NULL pointer dereference, address: 0000000000000078 #PF: supervisor read access in kernel mode #PF: errorcode(0x0000) - not-present page RIP: 0010:cxlpmemregionprobe+0x22e/0x360 [cxlpmem] Call Trace: <TASK> ? die+0x24/0x70 ? pagefaultoops+0x82/0x160 ? douseraddrfault+0x65/0x6b0 ? excpagefault+0x7d/0x170 ? asmexcpagefault+0x26/0x30 ? cxlpmemregionprobe+0x22e/0x360 [cxlpmem] ? cxlpmemregionprobe+0x1ac/0x360 [cxlpmem] cxlbusprobe+0x1b/0x60 [cxlcore] reallyprobe+0x173/0x410 ? pfxdeviceattachdriver+0x10/0x10 driverprobedevice+0x80/0x170 driverprobedevice+0x1e/0x90 deviceattachdriver+0x90/0x120 busforeachdrv+0x84/0xe0 deviceattach+0xbc/0x1f0 busprobedevice+0x90/0xa0 deviceadd+0x51c/0x710 devmcxladdpmemregion+0x1b5/0x380 [cxlcore] cxlbusprobe+0x1b/0x60 [cxlcore]

The cxlnvd of the memdev needs to be available during the pmem region probe. Currently the cxlnvd is registered after the endpoint port probe. The endpoint probe, in the case of autoassembly of regions, can cause a pmem region probe requiring the not yet available cxlnvd. Adjust the sequence so this dependency is met.

This requires adding a port parameter to cxlfindnvdimmbridge() that can be used to query the ancestor root port. The endpoint port is not yet available, but will share a common ancestor with its parent, so start the query from there instead.

Affected Software

4 affected componentsFixes available
redhat/kernel<6.9.8
6.9.8
redhat/kernel<6.10
6.10
Linux Linux kernel>=6.2<6.9.8
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1

Event History

Jul 29, 2024
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
Description
Dec 15, 2024
Data Sourced
via Ubuntu·12:30 PM
RemedyDescriptionSeverityAffected Software
May 1, 2025
Data Sourced
via Debian·12:34 AM
DescriptionAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-41085?

CVE-2024-41085 has a medium severity level due to the potential for kernel NULL pointer dereference.

2

How do I fix CVE-2024-41085?

To fix CVE-2024-41085, upgrade to kernel version 6.9.8 or higher if you are using Red Hat or the specific versions listed for Debian.

3

What versions of the Linux kernel are affected by CVE-2024-41085?

CVE-2024-41085 affects Linux kernel versions between 6.2 and 6.9.8, as well as several specific Debian versions.

4

What should I do if I cannot upgrade to the patched version for CVE-2024-41085?

If you cannot upgrade, consider implementing additional security measures to mitigate exposure to this vulnerability.

5

Is CVE-2024-41085 a remote exploitation vulnerability?

CVE-2024-41085 is not classified as a remote exploitation vulnerability but can lead to denial of service in specific conditions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203