cbcvebase.
CVE-2024-44948
published 2024-09-04

CVE-2024-44948: In the Linux kernel, the following vulnerability has been resolved: x86/mtrr: Check if fixed MTRRs exist before saving them MTRRs have an obsolete fixed…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.2th percentile
In the Linux kernel, the following vulnerability has been resolved: x86/mtrr: Check if fixed MTRRs exist before saving them MTRRs have an obsolete fixed variant for fine grained caching control of the 640K-1MB region that uses separate MSRs. This fixed variant has a separate capability bit in the MTRR capability MSR. So far all x86 CPUs which support MTRR have this separate bit set, so it went unnoticed that mtrr_save_state() does not check the capability bit before accessing the fixed MTRR MSRs. Though on a CPU that does not support the fixed MTRR capability this results in a #GP. The #GP itself is harmless because the RDMSR fault is handled gracefully, but results in a WARN_ON(). Add the missing capability check to prevent this.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux>= 2b1f6278d77c1f2f669346fc2bb48012b5e9495a < 34f36e6ee5bd7eff8b2adcd9fcaef369f752d82e34f36e6ee5bd7eff8b2adcd9fcaef369f752d82e
linuxlinux>= 2b1f6278d77c1f2f669346fc2bb48012b5e9495a < 06c1de44d378ec5439db17bf476507d68589bfe906c1de44d378ec5439db17bf476507d68589bfe9
linuxlinux>= 2b1f6278d77c1f2f669346fc2bb48012b5e9495a < 450b6b22acdaac67a18eaf5ed498421ffcf10051450b6b22acdaac67a18eaf5ed498421ffcf10051
linuxlinux>= 2b1f6278d77c1f2f669346fc2bb48012b5e9495a < ca7d00c5656d1791e28369919e3e10febe9c3b16ca7d00c5656d1791e28369919e3e10febe9c3b16
linuxlinux>= 2b1f6278d77c1f2f669346fc2bb48012b5e9495a < 8aa79dfb216b865e96ff890bc4ea71650f9bc8d78aa79dfb216b865e96ff890bc4ea71650f9bc8d7
linuxlinux>= 2b1f6278d77c1f2f669346fc2bb48012b5e9495a < 8a90d3fc7c24608548d3a750671f9dac21d1a4628a90d3fc7c24608548d3a750671f9dac21d1a462
linuxlinux>= 2b1f6278d77c1f2f669346fc2bb48012b5e9495a < 388f1c954019f253a8383f7eb733f38d541e10b6388f1c954019f253a8383f7eb733f38d541e10b6
linuxlinux>= 2b1f6278d77c1f2f669346fc2bb48012b5e9495a < 919f18f961c03d6694aa726c514184f2311a4614919f18f961c03d6694aa726c514184f2311a4614
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.10.6-16.10.6-1
linuxlinux_kernel>= 0 < 6.10.6-16.10.6-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 2.6.22 < 4.19.3204.19.320
linuxlinux_kernel>= 4.20 < 5.4.2825.4.282
linuxlinux_kernel>= 5.11 < 5.15.1655.15.165
linuxlinux_kernel>= 5.16 < 6.1.1056.1.105
linuxlinux_kernel>= 5.5 < 5.10.2245.10.224
linuxlinux_kernel>= 6.2 < 6.6.466.6.46

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.