PT-2024-7274 · Linux+4 · Linux Kernel+4
Published
2024-02-16
·
Updated
2025-09-29
·
CVE-2024-26761
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
The issue is related to the Linux CXL subsystem, which assumes that the host physical address (HPA) is equal to the system physical address (SPA). During HDM decoder setup, the DVSEC CXL range registers are checked to ensure the memory is enabled and the CXL range is within a HPA window described in a CFMWS structure of the CXL host bridge. If the HPA is not an SPA, the CXL range does not match a CFMWS window, causing the CXL memory range to be disabled, the HDM decoder to stop working, and resulting in system memory being disabled and a system hang during HDM decoder initialization. The change fixes a hardware hang but does not implement HPA/SPA translation.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Hat
Red Os
Suse