
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
CVE-2024-26762 affects the Linux kernel's CXL (Compute Express Link) error handling mechanism. The vulnerability was discovered in the cxl/pci component, specifically related to how RAS (Reliability, Availability, and Serviceability) errors are handled when a CXL.mem device is detached. The issue was disclosed in April 2024 and stems from the CXL error handler's attempt to perform optimistic error handling by unbinding the device from the cxl_mem driver after retrieving RAS register values (Kernel Git).
The vulnerability arises from the PCI AER (Advanced Error Reporting) model's incompatibility with CXL error handling. While PCI devices can use link reset for AER event recovery, the same action on CXL results in an unexpected memory hotplug of large memory amounts. The issue manifests when a subsequent AER notification occurs after the memdev unbind event, leading to crashes due to unmapped registers. This can result in page faults with errors like 'BUG: unable to handle page fault for address: ffa00000195e9100' in kernel mode (Kernel Git).
When exploited, this vulnerability can lead to system crashes due to page faults in kernel mode. The issue is particularly concerning as it affects the handling of memory-related operations in CXL devices, which could potentially impact system stability and reliability (Kernel Git).
The issue has been resolved by implementing a check for memdev bind before reaping status register values. The fix involves skipping RAS error handling if the CXL.mem device is detached. Additionally, there are discussions about potentially replacing the unbind and PCIERSRESULTDISCONNECT behavior with a new PCIERSRESULTPANIC in the longer term (Kernel Git).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”