CISA-2024-44948
Reported by Linux · Published September 4, 2024
In the Linux kernel, the following vulnerability has been resolved: x86/mtrr: Check if fixed MTRRs exist before saving them MTRRs have an obsolete fixed variant for fine grained caching control of the 640K-1MB region that uses separate MSRs. This fixed variant has a separate capability bit in the MTRR capability MSR. So far all x86 CPUs which support MTRR have this separate bit set, so it went unnoticed that mtrr_save_state() does not check the capability bit before accessing the fixed MTRR MSRs. Though on a CPU that does not support the fixed MTRR capability this results in a #GP. The #GP itself is harmless because the RDMSR fault is handled gracefully, but results in a WARN_ON(). Add the missing capability check to prevent this.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | 2b1f6278d77c1f2f669346fc2bb48012b5e9495a, 2b1f6278d77c1f2f669346fc2bb48012b5e9495a, 2b1f6278d77c1f2f669346fc2bb48012b5e9495a |
| Linux | Linux | 2.6.22, 0, 4.19.320 |
| Linux | Linux | *, 2b1f6278d77c1f2f669346fc2bb48012b5e9495a, 2b1f6278d77c1f2f669346fc2bb48012b5e9495a |
| linux | linux_kernel | 2.6.22, 2.6.22, 2.6.22 |
Timeline
- Sep 4, 2024 CVE Published
- Nov 3, 2025 CVE Updated