CVE-2024-43868
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/08/2024
Last modified:
03/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
riscv/purgatory: align riscv_kernel_entry<br />
<br />
When alignment handling is delegated to the kernel, everything must be<br />
word-aligned in purgatory, since the trap handler is then set to the<br />
kexec one. Without the alignment, hitting the exception would<br />
ultimately crash. On other occasions, the kernel&#39;s handler would take<br />
care of exceptions.<br />
This has been tested on a JH7110 SoC with oreboot and its SBI delegating<br />
unaligned access exceptions and the kernel configured to handle them.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.19 (including) | 6.1.117 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.61 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.10.4 (excluding) |
| cpe:2.3:o:linux:linux_kernel:6.11:rc1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/10ffafb456f293976c42f700578ef740467cb569
- https://git.kernel.org/stable/c/5d4aaf16a8255f7c71790e211724ba029609c5ff
- https://git.kernel.org/stable/c/6e62dab357eea12db0fc62dea94c7a892888e6e8
- https://git.kernel.org/stable/c/fb197c5d2fd24b9af3d4697d0cf778645846d6d5
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html



