---
cve: "CVE-2024-44948"
severity: "LOW"
cvss: 3.1
epss: "24%"
vendor: "Linux"
kev: false
exploited: false
published: "2024-09-04 19:15:29"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-18T05:40:19+02:00"
---

# CVE-2024-44948

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

x86/mtrr: Check if fixed MTRRs exist before saving them

MTRRs have an obsolete fixed variant for fine grained caching control
of the 640K-1MB region that uses separate MSRs. This fixed variant has
a separate capability bit in the MTRR capability MSR.

So far all x86 CPUs which support MTRR have this separate bit set, so it
went unnoticed that mtrr_save_state() does not check the capability bit
before accessing the fixed MTRR MSRs.

Though on a CPU that does not support the fixed MTRR capability this
results in a #GP.  The #GP itself is harmless because the RDMSR fault is
handled gracefully, but results in a WARN_ON().

Add the missing capability check to prevent this.

## Patch verfügbar (OSV)

- Kernel ≥ 4.19.320
- Kernel ≥ 5.4.282
- Kernel ≥ 5.10.224
- Kernel ≥ 5.15.165
- Kernel ≥ 6.1.105
- Kernel ≥ 6.6.46
- Kernel ≥ 6.10.5

## Referenzen

- <https://git.kernel.org/stable/c/34f36e6ee5bd7eff8b2adcd9fcaef369f752d82e>
- <https://git.kernel.org/stable/c/06c1de44d378ec5439db17bf476507d68589bfe9>
- <https://git.kernel.org/stable/c/450b6b22acdaac67a18eaf5ed498421ffcf10051>
- <https://git.kernel.org/stable/c/ca7d00c5656d1791e28369919e3e10febe9c3b16>
- <https://git.kernel.org/stable/c/8aa79dfb216b865e96ff890bc4ea71650f9bc8d7>
- <https://git.kernel.org/stable/c/8a90d3fc7c24608548d3a750671f9dac21d1a462>
- <https://git.kernel.org/stable/c/388f1c954019f253a8383f7eb733f38d541e10b6>
- <https://git.kernel.org/stable/c/919f18f961c03d6694aa726c514184f2311a4614>
- <https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html>
- <https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html>
- <https://cert-portal.siemens.com/productcert/html/ssa-265688.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-44948) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
