CVE-2024-42126
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-42126 affects the Linux kernel's PowerPC architecture implementation. The vulnerability involves nmi_enter()/nmi_exit() functions that handle per-CPU variables during real mode interrupt processing. The issue was discovered in July 2024 and affects systems where percpu allocation comes from vmalloc area, particularly when CONFIG_NEED_PER_CPU_PAGE_FIRST_CHUNK is enabled (Kernel Git).

Technical details

The vulnerability occurs when nmi_enter()/nmi_exit() functions access per-CPU variables during real mode interrupt handling (e.g., early HMI/MCE interrupt handler). The issue manifests specifically when percpu allocation comes from vmalloc area rather than the embedded first chunk. Early HMI/MCE handlers called through DEFINE_INTERRUPT_HANDLER_NMI() wrapper invoke these problematic nmi_enter/nmi_exit calls. The issue can be triggered using the kernel command line parameter 'percpu_alloc=page' to force percpu allocation from vmalloc area (Kernel Git).

Impact

When exploited, this vulnerability can lead to a kernel crash during machine_check_early execution. This is particularly evident in the crash trace showing failure in rcu_nmi_enter+0x24/0x110 during machine_check_early execution (Kernel Git).

Exploitability

The vulnerability requires specific conditions to be exploited, including having CONFIG_NEED_PER_CPU_PAGE_FIRST_CHUNK enabled and percpu allocation configured to use vmalloc area. It primarily affects PowerPC architecture systems under these specific configurations (Kernel Git).

Mitigation and workarounds

The issue has been fixed by avoiding the use of nmi_enter()/nmi_exit() in real mode when the percpu first chunk is not embedded. The fix has been implemented in various Linux kernel versions, including Ubuntu 24.04 LTS and 22.04 LTS. System administrators should update to the patched kernel versions that include this fix (Ubuntu Security).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

linux: 6.1.98-1

Fixed

bullseye

linux-6.1: 6.1.119-1~deb11u1

Fixed

sid

linux: 6.9.9-1

Fixed

trixie

linux: 6.9.9-1

Fixed

SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-80904MEDIUM5.9
  • Linux Kernel logoLinux Kernel
  • linux-oracle-7.0
NoYesSep 04, 2026
CVE-2026-80905MEDIUM5.5
  • Linux Kernel logoLinux Kernel
  • linux-azure-6.8
NoYesSep 04, 2026
CVE-2026-80913MEDIUM4.4
  • Linux Kernel logoLinux Kernel
  • linux-intel-iotg
NoYesSep 04, 2026
CVE-2026-80912MEDIUM4.4
  • Linux Kernel logoLinux Kernel
  • linux-lowlatency-hwe-5.15
NoYesSep 04, 2026
CVE-2026-80906NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-4.15
NoYesSep 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management