[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2024-41085":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T08:53:30.047Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":20,"aliases":21,"duplicate_of":9,"upstream":22,"downstream":23,"duplicates":56,"related":57,"reserved_at":9,"published_at":61,"modified_at":62,"state":63,"summary":64,"references_raw":73,"kevs":84,"epss":85,"epss_history":88,"metrics":333,"affected":339},"CVE-2024-41085","In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/mem: Fix no cxl_nvd during pmem region auto-assembling\n\nWhen CXL subsystem is auto-assembling a pmem region during cxl\nendpoint port probing, always hit below calltrace.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000078\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n RIP: 0010:cxl_pmem_region_probe+0x22e/0x360 [cxl_pmem]\n Call Trace:\n  \u003CTASK>\n  ? __die+0x24/0x70\n  ? page_fault_oops+0x82/0x160\n  ? do_user_addr_fault+0x65/0x6b0\n  ? exc_page_fault+0x7d/0x170\n  ? asm_exc_page_fault+0x26/0x30\n  ? cxl_pmem_region_probe+0x22e/0x360 [cxl_pmem]\n  ? cxl_pmem_region_probe+0x1ac/0x360 [cxl_pmem]\n  cxl_bus_probe+0x1b/0x60 [cxl_core]\n  really_probe+0x173/0x410\n  ? __pfx___device_attach_driver+0x10/0x10\n  __driver_probe_device+0x80/0x170\n  driver_probe_device+0x1e/0x90\n  __device_attach_driver+0x90/0x120\n  bus_for_each_drv+0x84/0xe0\n  __device_attach+0xbc/0x1f0\n  bus_probe_device+0x90/0xa0\n  device_add+0x51c/0x710\n  devm_cxl_add_pmem_region+0x1b5/0x380 [cxl_core]\n  cxl_bus_probe+0x1b/0x60 [cxl_core]\n\nThe cxl_nvd of the memdev needs to be available during the pmem region\nprobe. Currently the cxl_nvd is registered after the endpoint port probe.\nThe endpoint probe, in the case of autoassembly of regions, can cause a\npmem region probe requiring the not yet available cxl_nvd. Adjust the\nsequence so this dependency is met.\n\nThis requires adding a port parameter to cxl_find_nvdimm_bridge() that\ncan be used to query the ancestor root port. The endpoint port is not\nyet available, but will share a common ancestor with its parent, so\nstart the query from there instead.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-476","NULL Pointer Dereference","The product dereferences a pointer that it expects to be valid but is NULL.","weakness","Stable","Base","Medium",[],[],[],[],[24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54],{"_key":25},"SUSE-SU-2025:02254-1",{"_key":27},"SUSE-SU-2025:02307-1",{"_key":29},"SUSE-SU-2025:02333-1",{"_key":31},"UBUNTU-CVE-2024-41085",{"_key":33},"DEBIAN-CVE-2024-41085",{"_key":35},"RHSA-2024:9315",{"_key":37},"USN-7089-1",{"_key":39},"USN-7089-2",{"_key":41},"USN-7089-3",{"_key":43},"USN-7089-4",{"_key":45},"USN-7089-5",{"_key":47},"USN-7089-6",{"_key":49},"USN-7089-7",{"_key":51},"USN-7090-1",{"_key":53},"USN-7095-1",{"_key":55},"USN-7156-1",[],[58,59,60],{"_key":25},{"_key":27},{"_key":29},"2024-07-29T15:48:01.267Z","2026-05-11T20:25:54.317Z","Modified",{"cisa_kev":65,"cisa_ransomware":65,"cisa_vendor":9,"epss_severity":66,"epss_score":67,"severity":68,"severity_score":69,"severity_version":70,"severity_source":71,"severity_vector":72,"severity_status":63},false,"low",0.00009,"medium",5.5,"v3.1","nvd","CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",[74,80],{"url":75,"sources":76,"tags":78},"https://git.kernel.org/stable/c/1d064e4fbebcf5b18dc10c1f3973487eb163b600",[77,71],"cve.org",[79],"Patch",{"url":81,"sources":82,"tags":83},"https://git.kernel.org/stable/c/84ec985944ef34a34a1605b93ce401aa8737af96",[77,71],[79],[],{"date":86,"score":67,"percentile":87},"2026-06-03",0.01028,[89,92,95,98,101,104,106,109,111,114,117,119,121,123,125,129,132,135,139,142,145,147,150,153,156,158,161,164,167,170,173,176,179,182,184,187,190,193,196,198,200,202,205,208,210,213,216,219,221,224,227,230,233,236,239,242,244,246,248,250,252,255,257,260,262,264,266,269,272,274,277,280,283,285,287,289,292,295,298,301,304,307,310,312,315,318,321,324,327,330],{"date":90,"score":67,"percentile":91},"2025-11-04",0.00665,{"date":93,"score":67,"percentile":94},"2025-11-05",0.00668,{"date":96,"score":67,"percentile":97},"2025-11-06",0.00669,{"date":99,"score":67,"percentile":100},"2025-11-07",0.00671,{"date":102,"score":67,"percentile":103},"2025-11-08",0.0067,{"date":105,"score":67,"percentile":97},"2025-11-09",{"date":107,"score":67,"percentile":108},"2025-11-10",0.00666,{"date":110,"score":67,"percentile":91},"2025-11-11",{"date":112,"score":67,"percentile":113},"2025-11-12",0.00662,{"date":115,"score":67,"percentile":116},"2025-11-13",0.00661,{"date":118,"score":67,"percentile":91},"2025-11-14",{"date":120,"score":67,"percentile":97},"2025-11-15",{"date":122,"score":67,"percentile":94},"2025-11-16",{"date":124,"score":67,"percentile":108},"2025-11-17",{"date":126,"score":127,"percentile":128},"2025-11-18",0.00065,0.15902,{"date":130,"score":127,"percentile":131},"2025-11-19",0.15913,{"date":133,"score":127,"percentile":134},"2025-11-20",0.15897,{"date":136,"score":137,"percentile":138},"2025-11-21",0.0001,0.00709,{"date":140,"score":137,"percentile":141},"2025-11-22",0.00708,{"date":143,"score":67,"percentile":144},"2025-11-23",0.00673,{"date":146,"score":67,"percentile":94},"2025-11-24",{"date":148,"score":67,"percentile":149},"2025-11-25",0.00667,{"date":151,"score":67,"percentile":152},"2025-11-26",0.00659,{"date":154,"score":67,"percentile":155},"2025-11-27",0.00658,{"date":157,"score":67,"percentile":113},"2025-11-28",{"date":159,"score":67,"percentile":160},"2025-11-29",0.00677,{"date":162,"score":67,"percentile":163},"2025-11-30",0.00679,{"date":165,"score":67,"percentile":166},"2025-12-01",0.00681,{"date":168,"score":67,"percentile":169},"2025-12-02",0.00678,{"date":171,"score":67,"percentile":172},"2025-12-03",0.00683,{"date":174,"score":67,"percentile":175},"2025-12-04",0.00684,{"date":177,"score":67,"percentile":178},"2025-12-05",0.00691,{"date":180,"score":67,"percentile":181},"2025-12-06",0.00688,{"date":183,"score":67,"percentile":181},"2025-12-07",{"date":185,"score":67,"percentile":186},"2025-12-08",0.00692,{"date":188,"score":67,"percentile":189},"2025-12-09",0.00706,{"date":191,"score":67,"percentile":192},"2025-12-10",0.00717,{"date":194,"score":67,"percentile":195},"2025-12-11",0.00715,{"date":197,"score":67,"percentile":192},"2025-12-12",{"date":199,"score":67,"percentile":195},"2025-12-13",{"date":201,"score":67,"percentile":195},"2025-12-14",{"date":203,"score":67,"percentile":204},"2025-12-15",0.0071,{"date":206,"score":67,"percentile":207},"2025-12-16",0.00713,{"date":209,"score":67,"percentile":195},"2025-12-17",{"date":211,"score":137,"percentile":212},"2025-12-18",0.00747,{"date":214,"score":137,"percentile":215},"2025-12-19",0.00751,{"date":217,"score":137,"percentile":218},"2025-12-20",0.00749,{"date":220,"score":137,"percentile":212},"2025-12-21",{"date":222,"score":137,"percentile":223},"2025-12-22",0.00752,{"date":225,"score":137,"percentile":226},"2025-12-23",0.0075,{"date":228,"score":137,"percentile":229},"2025-12-24",0.00753,{"date":231,"score":137,"percentile":232},"2025-12-25",0.00756,{"date":234,"score":137,"percentile":235},"2025-12-26",0.00759,{"date":237,"score":137,"percentile":238},"2025-12-27",0.00757,{"date":240,"score":137,"percentile":241},"2025-12-28",0.00755,{"date":243,"score":137,"percentile":223},"2025-12-29",{"date":245,"score":137,"percentile":226},"2025-12-30",{"date":247,"score":137,"percentile":212},"2025-12-31",{"date":249,"score":137,"percentile":223},"2026-01-01",{"date":251,"score":137,"percentile":238},"2026-01-02",{"date":253,"score":137,"percentile":254},"2026-01-03",0.0076,{"date":256,"score":137,"percentile":218},"2026-01-04",{"date":258,"score":67,"percentile":259},"2026-01-05",0.0072,{"date":261,"score":67,"percentile":192},"2026-01-06",{"date":263,"score":67,"percentile":195},"2026-01-07",{"date":265,"score":67,"percentile":259},"2026-01-08",{"date":267,"score":67,"percentile":268},"2026-01-09",0.00727,{"date":270,"score":67,"percentile":271},"2026-01-10",0.0073,{"date":273,"score":67,"percentile":271},"2026-01-11",{"date":275,"score":67,"percentile":276},"2026-01-12",0.00728,{"date":278,"score":67,"percentile":279},"2026-01-13",0.00726,{"date":281,"score":67,"percentile":282},"2026-01-14",0.00725,{"date":284,"score":67,"percentile":276},"2026-01-15",{"date":286,"score":67,"percentile":276},"2026-01-16",{"date":288,"score":67,"percentile":276},"2026-01-17",{"date":290,"score":137,"percentile":291},"2026-01-18",0.0077,{"date":293,"score":137,"percentile":294},"2026-01-19",0.00768,{"date":296,"score":137,"percentile":297},"2026-01-20",0.00763,{"date":299,"score":137,"percentile":300},"2026-01-21",0.00761,{"date":302,"score":137,"percentile":303},"2026-01-22",0.00762,{"date":305,"score":137,"percentile":306},"2026-01-23",0.00772,{"date":308,"score":137,"percentile":309},"2026-01-24",0.00779,{"date":311,"score":137,"percentile":309},"2026-01-25",{"date":313,"score":137,"percentile":314},"2026-01-26",0.0078,{"date":316,"score":137,"percentile":317},"2026-01-27",0.00784,{"date":319,"score":137,"percentile":320},"2026-01-28",0.00781,{"date":322,"score":137,"percentile":323},"2026-01-29",0.00783,{"date":325,"score":137,"percentile":326},"2026-01-30",0.00795,{"date":328,"score":137,"percentile":329},"2026-01-31",0.00802,{"date":331,"score":67,"percentile":332},"2026-02-01",0.00767,[334],{"source":71,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":335,"cvss_v4_0":9},{"baseScore":69,"baseSeverity":336,"vectorString":72,"impactScore":337,"exploitabilityScore":338},"MEDIUM",6,4.6,[340,357],{"ecosystem":9,"name":341,"vendor":342,"product":342,"cpe_part":343,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":344},"Linux","linux","a",[345,352,355],{"version":346,"is_range":347,"range_type":77,"version_start":348,"version_start_type":349,"version_end":350,"version_end_type":351,"fixed_in":9},">= f17b558d6663101f876a1d9cbbad3de0c8f4ce4d, \u003C 1d064e4fbebcf5b18dc10c1f3973487eb163b600",true,"f17b558d6663101f876a1d9cbbad3de0c8f4ce4d","including","1d064e4fbebcf5b18dc10c1f3973487eb163b600","excluding",{"version":353,"is_range":347,"range_type":77,"version_start":348,"version_start_type":349,"version_end":354,"version_end_type":351,"fixed_in":9},">= f17b558d6663101f876a1d9cbbad3de0c8f4ce4d, \u003C 84ec985944ef34a34a1605b93ce401aa8737af96","84ec985944ef34a34a1605b93ce401aa8737af96",{"version":356,"is_range":65,"range_type":77,"version_start":356,"version_start_type":349,"version_end":356,"version_end_type":349,"fixed_in":9},"6.2",{"ecosystem":9,"name":358,"vendor":342,"product":359,"cpe_part":360,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":361},"linux kernel","linux_kernel","o",[362],{"version":363,"is_range":347,"range_type":364,"version_start":356,"version_start_type":349,"version_end":365,"version_end_type":351,"fixed_in":9},"gte6.2_lt6.9.8","cpe","6.9.8"]