PT-2026-34913 · Linux · Linux Kernel
Published
2026-04-24
·
Updated
2026-04-29
·
CVE-2026-31561
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the x86 CPU handling where the
X86 CR4 FRED bit was included in the CR4 pinned bits mask. During boot, FRED is initialized on the Bootstrap Processor (BSP) and subsequently on Application Processors (APs), creating a window where exceptions cannot be handled. In SEV-ES, SEV-SNP, or TDX guests, triggering exceptions during this window can lead to a triple fault because FRED Model Specific Registers (MSRs) are not yet configured. Previous attempts to fix this by temporarily disabling CR4 pinning when an AP is not online introduced a security risk, as an attacker could modify the online bit in read-write memory to disable CR4 pinning and subsequently disable Supervisor Mode Execution Prevention (SMEP) or Supervisor Mode Access Prevention (SMAP).Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel