CVE-2024-50226·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: cxl/port: Fix use-after-free, permit out-of-order decoder shutdown In support of investigating an initialization failure report [1], cxl_test was updated to register mock memory-devices after the mock root-port/bus device had been registered. That led to cxl_test crashing with a use-after-free bug with the following signature: cxl_port_attach_region: cxl region3: cxl_host_bridge.0:port3 decoder3.0 add: mem0:decoder7.0 @ 0 next: cxl_switch_uport.0 nr_eps: 1 nr_targets: 1 cxl_port_attach_region: cxl region3: cxl_host_bridge.0:port3 decoder3.0 add: mem4:decoder14.0 @ 1 next: cxl_switch_uport.0 nr_eps: 2 nr_targets: 1 cxl_port_setup_targets: cxl region3: cxl_switch_uport.0:port6 target[0] = cxl_switch_dport.0 for mem0:decoder7.0 @ 0 1) cxl_port_setup_targets: cxl region3: cxl_switch_uport.0:port6 target[1] = cxl_switch_dport.4 for mem4:decoder14.0 @ 1 [..] cxld_unregister: cxl decoder14.0: cxl_region_decode_reset: cxl_region region3: mock_decoder_reset: cxl_port port3: decoder3.0 reset 2) mock_decoder_reset: cxl_port port3: decoder3.0: out of order reset, expected decoder3.1 cxl_endpoint_decoder_release: cxl decoder14.0: [..] cxld_unregister: cxl decoder7.0: 3) cxl_region_decode_reset: cxl_region region3: Oops: general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b6bc3: 0000 [#1] PREEMPT SMP PTI [..] RIP: 0010:to_cxl_port+0x8/0x60 [cxl_core] [..] Call Trace: <TASK> cxl_region_decode_reset+0x69/0x190 [cxl_core] cxl_region_detach+0xe8/0x210 [cxl_core] cxl_decoder_kill_region+0x27/0x40 [cxl_core] cxld_unregister+0x5d/0x60 [cxl_core] At 1) a region has been established with 2 endpoint decoders (7.0 and 14.0). Those endpoints share a common switch-decoder in the topology (3.0). At teardown, 2), decoder14.0 is the first to be removed and hits the "out of order reset case" in the switch decoder. The effect though is that region3 cleanup is aborted leaving it in-tact and referencing decoder14.0. At 3) the second attempt to teardown region3 trips over the stale decoder14.0 object which has long since been deleted. The fix here is to recognize that the CXL specification places no mandate on in-order shutdown of switch-decoders, the driver enforces in-order allocation, and hardware enforces in-order commit. So, rather than fail and leave objects dangling, always remove them. In support of making cxl_region_decode_reset() always succeed, cxl_region_invalidate_memregion() failures are turned into warnings. Crashing the kernel is ok there since system integrity is at risk if caches cannot be managed around physical address mutation events like CXL region destruction. A new device_for_each_child_reverse_from() is added to cleanup port->commit_end after all dependent decoders have been disabled. In other words if decoders are allocated 0->1->2 and disabled 1->2->0 then port->commit_end only decrements from 2 after 2 has been disabled, and it decrements all the way to zero since 1 was disabled previously.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.11.7
- Published
- 2024-11-09
Affected versions
From: 6.7
Until: 6.11.7
Fixed in: 6.11.7
How to fix this CVE
Update your Linux kernel to version 6.11.7 or later to remediate this use-after-free vulnerability affecting CXL (Compute Express Link) memory decoder management. The vulnerability manifests when decoders are shut down out-of-order, causing kernel crashes and potential system instability. Immediate kernel patching is recommended for systems using CXL-capable hardware.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Check installed kernel version: uname -r | awk -F'.' '{print $1"."$2"."$3}'
- Verify if CXL support is enabled: grep -i cxl /boot/config-$(uname -r) or lsmod | grep cxl
- Search dmesg for CXL decoder errors: dmesg | grep -i 'cxl.*decoder\|out of order reset'
- Confirm patch application: grep -i 'use-after-free\|out-of-order decoder' /proc/version or verify kernel build date is after the fix commit timestamp
FAQ
What is CVE-2024-50226?
CVE-2024-50226 is a use-after-free vulnerability in the Linux kernel's CXL port driver that occurs when memory decoders attached to a common switch are deregistered in non-sequential order, causing kernel crashes and memory corruption.
Is CVE-2024-50226 being actively exploited?
No, CVE-2024-50226 is not listed in CISA's Known Exploited Vulnerabilities catalog and has no public exploits available. It requires specific CXL hardware configuration and out-of-order device removal to trigger.
What versions of Kernel are affected by CVE-2024-50226?
Linux kernel versions 6.7 through 6.11.6 are affected. The vulnerability is patched in kernel 6.11.7 and later.
How do I check if my server is vulnerable to CVE-2024-50226?
Run: uname -r && grep -c cxl /boot/config-$(uname -r). If the kernel version is between 6.7 and 6.11.6 and CXL is enabled (grep returns 1), the system is vulnerable.
Does Defensia detect CVE-2024-50226?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Linux kernel is installed on a monitored server, CVE-2024-50226 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-50226. Free for 1 server.
Get started free