Executive brief
A vulnerability in the Linux kernel's handling of x86 processor memory settings could cause a system warning or instability on specific hardware. The issue occurs when the system attempts to save memory caching states on processors that do not support certain legacy features. While the impact is generally limited to system warnings, it could potentially be used to trigger minor service disruptions on affected machines.
Technical details
A vulnerability exists in the x86 MTRR (Memory Type Range Register) implementation within the Linux kernel. The function mtrr_save_state() lacked a check for the 'fixed MTRR' capability bit before attempting to access related Model Specific Registers (MSRs). On CPUs that support MTRRs but lack the fixed variant (used for the 640K-1MB region), this results in a General Protection Fault (#GP) during RDMSR operations. While the kernel handles the fault gracefully, it triggers a WARN_ON() which can lead to system instability or log flooding. The fix adds a check for mtrr_state.have_fixed before proceeding with the save operation.
Affected products
- Linux Linux Kernel 2.6.22 to 4.19.320, 4.20 to 5.4.282, 5.5 to 5.10.224, 5.11 to 5.15.165, 5.16 to 6.1.105, 6.2 to 6.6.46, 6.7 to 6.10.5, 6.11-rc1, 6.11-rc2
Timeline
- 2024-09-04: advisory: CVE-2024-44948 published by kernel.org and NVD
- 2024-08-19: patched: Fix committed to various stable kernel branches
References
- https://git.kernel.org/stable/c/06c1de44d378ec5439db17bf476507d68589bfe9
- https://git.kernel.org/stable/c/34f36e6ee5bd7eff8b2adcd9fcaef369f752d82e
- https://git.kernel.org/stable/c/388f1c954019f253a8383f7eb733f38d541e10b6
- https://git.kernel.org/stable/c/450b6b22acdaac67a18eaf5ed498421ffcf10051
- https://git.kernel.org/stable/c/8a90d3fc7c24608548d3a750671f9dac21d1a462
- https://git.kernel.org/stable/c/8aa79dfb216b865e96ff890bc4ea71650f9bc8d7
- https://git.kernel.org/stable/c/919f18f961c03d6694aa726c514184f2311a4614