PT-2024-7274 · Linux+4 · Linux Kernel+4

Published

2024-02-16

·

Updated

2025-09-29

·

CVE-2024-26761

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to the Linux CXL subsystem, which assumes that the host physical address (HPA) is equal to the system physical address (SPA). During HDM decoder setup, the DVSEC CXL range registers are checked to ensure the memory is enabled and the CXL range is within a HPA window described in a CFMWS structure of the CXL host bridge. If the HPA is not an SPA, the CXL range does not match a CFMWS window, causing the CXL memory range to be disabled, the HDM decoder to stop working, and resulting in system memory being disabled and a system hang during HDM decoder initialization. The change fixes a hardware hang but does not implement HPA/SPA translation.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
BDU:2024-08626
CVE-2024-26761
DSA-5658-1
INFSA-2024_9315
OPENSUSE-SU-2024_3984-1
OPENSUSE-SU-2024_3986-1
RHSA-2024:9315
RHSA-2024_9315
SUSE-SU-2024:2135-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2973-1
SUSE-SU-2024:3984-1
SUSE-SU-2024:3986-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
SUSE-SU-2025:20249-1

Affected Products

Astra Linux
Linux Kernel
Red Hat
Red Os
Suse