Database/Kernel, userspace & hypervisor
Linux kernel CXL: NULL dereference when a pmem region is auto-assembled before cxl_nvd registers
Impact
On hosts with CXL persistent memory, the endpoint port probe can trigger auto-assembly of a pmem region before the memdev's cxl_nvd object exists, and cxl_pmem_region_probe() dereferences the missing object - a kernel NULL pointer dereference and oops. The effect is availability only: the box crashes or the CXL memory fails to come up, which on a GPU node means an unplanned outage rather than a drain. There is no attacker input here - the trigger is device-probe ordering during boot or CXL hotplug, not anything a tenant submits, so the local/low-privilege framing in the CVSS vector overstates the reachable attack surface. Nodes with no CXL persistent memory configured, which is still most GPU hosts, are not affected at all.
Who can reach it
No practical attacker path established by the record. Reached through CXL endpoint port probing and pmem region auto-assembly, i.e. at boot or on CXL device hotplug on hardware with CXL persistent memory present; a local user with physical or hotplug control over a CXL device is the closest thing to a trigger.
What to do
Pick up a stable kernel containing the fix (commits 1d064e4fbebcf5b18dc10c1f3973487eb163b600, 84ec985944ef34a34a1605b93ce401aa8737af96, bc262c6d32b6c1715e64220e2cbfa64a225cd266) and reboot each affected node - a kernel change on the CXL probe path cannot be applied live. Nodes without CXL persistent memory can be deferred to the next routine kernel window. The record names no fixed distribution version; check your vendor's kernel errata rather than assuming a number.
References
Related entries
- Linux drm/xe GPU kernel driver (display opregion): A resource leak in the xe driver's display opregion handlingCVE-2024-44980 · Linux drm/xe GPU kernel driver (display opregion)Medium
- Linux kernel (drivers/pci/hotplug): The hotplug driver disables MSI/MSI-X during slot unregistration after the MSI dataCVE-2024-46761 · Linux kernel (drivers/pci/hotplug)Medium
- Linux kernel (drivers/gpu/drm/xe): Same per-client accounting path, different failure - if the fdinfo read drops theCVE-2024-46867 · Linux kernel (drivers/gpu/drm/xe)Medium
- Linux kernel BPF verifier: sign-extended packet-pointer loads produce an invalid skb->data addressCVE-2024-47702 · Linux kernel BPF verifier (sign-extended loads of __sk_buff data/data_end/data_meta)Medium
- Linux kernel (drivers/gpu/drm/xe): User VM_BIND work is scheduled onto engines that can themselves take page faultsCVE-2024-47729 · Linux kernel (drivers/gpu/drm/xe)Medium
- Linux kernel x86/mm: identity maps built from 1 GB pages cover unrequested reserved memoryCVE-2024-50017 · Linux kernel x86 identity mapping (ident_pud_init GB-page mapping)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.