CVE-2024-50193

HIGH

Linux Kernel < 5.10.228, 5.11.0-5.15.168, 5.16.0-6.1.113, 6.2.0-6.6.57, 6.7.0-6.11.4 - NMI Return Info Disclosure

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: x86/entry_32: Clear CPU buffers after register restore in NMI return CPU buffers are currently cleared after call to exc_nmi, but before register state is restored. This may be okay for MDS mitigation but not for RDFS. Because RDFS mitigation requires CPU buffers to be cleared when registers don't have any sensitive data. Move CLEAR_CPU_BUFFERS after RESTORE_ALL_NMI.

Scores

CVSS v3 7.1
EPSS 0.0021
EPSS Percentile 11.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (27)
linux/Kernel < 5.10.228linux
linux/Kernel 5.11.0 - 5.15.169linux
linux/Kernel 5.16.0 - 6.1.114linux
linux/Kernel 6.2.0 - 6.6.58linux
linux/Kernel 6.7.0 - 6.11.5linux
Linux/Linux < 6.8
Linux/Linux 2e3087505ddb8ba2d3d4c81306cca11e868fcdb9 - 43778de19d2ef129636815274644b9c16e78c66b
Linux/Linux 5.10.215 - 5.10.228
Linux/Linux 5.10.228 - 5.10.*
Linux/Linux 5.15.154 - 5.15.169
... and 17 more
Published Nov 08, 2024
Tracked Since Feb 18, 2026