Tracker / CVE-2024-40944
CVE-2024-40944
Medium 5.5
In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Fix bug with call depth tracking The call to cc_platform_has() triggers a fault and system crash if call depth tracking is active because the GS segment has been reset by load_segments() and GS_BASE is now 0 but call depth tracking uses per-CPU variables to operate. Call cc_platform_has() earlier in the function when GS is still valid. [ bp: Massage. ]
Affected products and versions
| linux | linux_kernel |
|---|---|
| linux | linux_kernel · 6.2 → 6.6.35 |
| linux | linux_kernel · 6.7 → 6.9.6 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.