In the Linux kernel, the following vulnerability has been resolved: cxl/mem: Fix no cxl_nvd during pmem region auto-assembling When CXL subsystem is… (CVE-2024-41085)
A null pointer dereference vulnerability (CVE-2024-41085) in the Linux kernel's CXL subsystem was fixed. The issue occurs during the auto-assembling of a persistent memory (pmem) region when the cxl_nvd device is not yet registered, causing a kernel crash. The fix adjusts the probe sequence to ensure the cxl_nvd is available when needed.
AI Analysis
Technical Summary
CVE-2024-41085 is a vulnerability in the Linux kernel's CXL memory subsystem where a null pointer dereference occurs during the auto-assembling of a pmem region in the cxl endpoint port probing process. The root cause is that the cxl_nvd device is registered after the endpoint port probe, but the pmem region probe requires it to be available earlier. This leads to a kernel NULL pointer dereference and a crash. The fix involves changing the probe sequence and adding a port parameter to cxl_find_nvdimm_bridge() to query the ancestor root port, ensuring the dependency is met before the pmem region probe.
Potential Impact
The vulnerability causes a kernel NULL pointer dereference resulting in a kernel crash (denial of service) when the CXL subsystem auto-assembles a pmem region. There is no indication of confidentiality or integrity impact.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to adjust the probe sequence so that the cxl_nvd device is available during the pmem region probe. Users should apply the official kernel update containing this fix once available. Patch status is not explicitly confirmed in the input; check the vendor advisory for the current remediation guidance.
In the Linux kernel, the following vulnerability has been resolved: cxl/mem: Fix no cxl_nvd during pmem region auto-assembling When CXL subsystem is… (CVE-2024-41085)
Description
A null pointer dereference vulnerability (CVE-2024-41085) in the Linux kernel's CXL subsystem was fixed. The issue occurs during the auto-assembling of a persistent memory (pmem) region when the cxl_nvd device is not yet registered, causing a kernel crash. The fix adjusts the probe sequence to ensure the cxl_nvd is available when needed.
CVSS v3.1
Score 5.5medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2024-41085 is a vulnerability in the Linux kernel's CXL memory subsystem where a null pointer dereference occurs during the auto-assembling of a pmem region in the cxl endpoint port probing process. The root cause is that the cxl_nvd device is registered after the endpoint port probe, but the pmem region probe requires it to be available earlier. This leads to a kernel NULL pointer dereference and a crash. The fix involves changing the probe sequence and adding a port parameter to cxl_find_nvdimm_bridge() to query the ancestor root port, ensuring the dependency is met before the pmem region probe.
Potential Impact
The vulnerability causes a kernel NULL pointer dereference resulting in a kernel crash (denial of service) when the CXL subsystem auto-assembles a pmem region. There is no indication of confidentiality or integrity impact.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to adjust the probe sequence so that the cxl_nvd device is available during the pmem region probe. Users should apply the official kernel update containing this fix once available. Patch status is not explicitly confirmed in the input; check the vendor advisory for the current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-2qvq-p8h3-vf5j
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2024-41085"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6ac13969a43b0b3b89d5fbbf
Added to database: 10/03/2026, 17:20:41 UTC
Last enriched: 10/03/2026, 17:24:48 UTC
Last updated: 10/04/2026, 02:45:59 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.