PT-2024-10460 · Linux+6 · Linux Kernel+6

Mahesh Salgaonkar

+1

·

Published

2024-07-30

·

Updated

2026-03-14

·

CVE-2024-42126

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the powerpc component of the Linux kernel, where the nmi enter() and nmi exit() functions touch per CPU variables, potentially leading to a kernel crash when invoked during real mode interrupt handling. This can occur if percpu allocation comes from the vmalloc area, particularly when the CONFIG NEED PER CPU PAGE FIRST CHUNK is enabled. The vulnerability can be triggered through early HMI/MCE interrupt handlers called via the DEFINE INTERRUPT HANDLER NMI() wrapper. Technical details include the involvement of rcu nmi enter() and machine check early() functions, with specific register values and interrupt handling mechanisms mentioned.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01000
CVE-2024-42126
DLA-4008-1
MGASA-2024-0277
MGASA-2024-0278
OESA-2024-1960
OESA-2024-1994
OESA-2024-1995
OESA-2024-2031
OPENSUSE-SU-2024_3190-1
OPENSUSE-SU-2024_3209-1
OPENSUSE-SU-2024_3408-1
OPENSUSE-SU-2024_3483-1
SUSE-SU-2024:3190-1
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3209-1
SUSE-SU-2024:3227-1
SUSE-SU-2024:3383-1
SUSE-SU-2024:3408-1
SUSE-SU-2024:3483-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1
USN-7089-1
USN-7089-2
USN-7089-3
USN-7089-4
USN-7089-5
USN-7089-6
USN-7089-7
USN-7090-1
USN-7095-1
USN-7100-1
USN-7100-2
USN-7123-1
USN-7144-1
USN-7156-1
USN-7194-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu