---
id: CVE-2024-41085
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  cxl/mem: Fix no cxl_nvd during pmem region auto-assembling

  When CXL subsystem is auto-assembling a pmem region during cxl
  endpoint port probing, always hit below callt…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  cxl/mem: Fix no cxl_nvd during pmem region auto-assembling

  When CXL subsystem is auto-assembling a pmem region during cxl
  endpoint port probing, always hit below callt…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-476
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 6.2, < 6.9.8'
patched:
  - linux_kernel 6.9.8
published: '2024-07-29'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T11:17:30.730'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-41085'
references:
  - url: 'https://git.kernel.org/stable/c/1d064e4fbebcf5b18dc10c1f3973487eb163b600'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/84ec985944ef34a34a1605b93ce401aa8737af96'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bc262c6d32b6c1715e64220e2cbfa64a225cd266'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/1d064e4fbebcf5b18dc10c1f3973487eb163b600'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/84ec985944ef34a34a1605b93ce401aa8737af96'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2024-09-10T16:20:52.180696Z'
epss: 0.00212
epssPercentile: 0.10384
ingestedAt: '2026-10-03T11:43:42.102Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

cxl/mem: Fix no cxl_nvd during pmem region auto-assembling

When CXL subsystem is auto-assembling a pmem region during cxl
endpoint port probing, always hit below calltrace.

 BUG: kernel NULL pointer dereference, address: 0000000000000078
 #PF: supervisor read access in kernel mode
 #PF: error_code(0x0000) - not-present page
 RIP: 0010:cxl_pmem_region_probe+0x22e/0x360 [cxl_pmem]
 Call Trace:
  <TASK>
  ? __die+0x24/0x70
  ? page_fault_oops+0x82/0x160
  ? do_user_addr_fault+0x65/0x6b0
  ? exc_page_fault+0x7d/0x170
  ? asm_exc_page_fault+0x26/0x30
  ? cxl_pmem_region_probe+0x22e/0x360 [cxl_pmem]
  ? cxl_pmem_region_probe+0x1ac/0x360 [cxl_pmem]
  cxl_bus_probe+0x1b/0x60 [cxl_core]
  really_probe+0x173/0x410
  ? __pfx___device_attach_driver+0x10/0x10
  __driver_probe_device+0x80/0x170
  driver_probe_device+0x1e/0x90
  __device_attach_driver+0x90/0x120
  bus_for_each_drv+0x84/0xe0
  __device_attach+0xbc/0x1f0
  bus_probe_device+0x90/0xa0
  device_add+0x51c/0x710
  devm_cxl_add_pmem_region+0x1b5/0x380 [cxl_core]
  cxl_bus_probe+0x1b/0x60 [cxl_core]

The cxl_nvd of the memdev needs to be available during the pmem region
probe. Currently the cxl_nvd is registered after the endpoint port probe.
The endpoint probe, in the case of autoassembly of regions, can cause a
pmem region probe requiring the not yet available cxl_nvd. Adjust the
sequence so this dependency is met.

This requires adding a port parameter to cxl_find_nvdimm_bridge() that
can be used to query the ancestor root port. The endpoint port is not
yet available, but will share a common ancestor with its parent, so
start the query from there instead.

## Affected

- `linux_kernel >= 6.2, < 6.9.8`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.9.8`
