Description
In the Linux kernel, the following vulnerability has been resolved:

cxl/mce: Make the MCE notifier per-region

Flavien Solt reported lifetime issues with the CXL MCE notifier, which
can lead to NULL dereferences and use-after-free in the MCE handler.
The notifier was registered per memory device and stored in 'struct
cxl_memdev_state', even though it only needs the region state (the
region's SPA range and its extended linear cache size).

Instead of keeping the memory device and endpoint alive, the correct fix
is to move the notifier into 'struct cxl_region' and register it from
cxl_region_probe() as it should be a per-region notifier. Setup the
registration to only happen for regions that have an extended linear
cache as that is the only current usage.

Remove cxl_port_get_spa_cache_alias() as it is now dead code.

[ dj: Update dev_warn() when notifier fails due to kconfig. (Ben) ]
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel NULL dereference/use-after-free
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from a lifetime management flaw in the Linux kernel's CXL Memory Control Engine notifier. The notifier was freed prematurely. When the kernel later accessed the stale notifier reference during a machine‑exception event, it performed a NULL pointer dereference or a use-after‑free, causing a kernel crash. The weakness is a classic invalid memory reference (CWE-476).

Affected Systems

All Linux kernel releases that contain the pre‑fix notifier implementation are affected. The fix is included in commits referenced in the CVE description and is available in kernel versions that incorporate those changes. Systems running any older kernel that has not been updated to include those commits remain vulnerable.

Risk and Exploitability

The CVSS score of 7.8 classifies the flaw as high severity. The EPSS score of < 1 % indicates a very low exploitation probability. The CVE is not listed in the CISA KEV catalog. Because the flaw requires a CXL device to trigger the notifier and a machine‑exception event, the attack surface is narrow. The likely attack vector is an attacker with ability to cause or observe a machine‑exception on a system with CXL support. Given these constraints, widespread exploitation is unlikely, but the kernel crash results in denial of service, so timely patching is essential.

Generated by OpenCVE AI on September 15, 2026 at 21:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that includes the commit adding per‑region notifier for CXL MCE, thereby eliminating the NULL dereference/use‑after‑free flaw (CWE-476).
  • If upgrading is not possible immediately, compile the kernel with the CXL MCE driver disabled (CONFIG_CXL_MCE=n) to prevent the vulnerable notifier from being registered.
  • Monitor kernel logs (dmesg/journal) for CXL MCE errors and consider postponing the use of CXL hardware until a patched kernel is available.

Generated by OpenCVE AI on September 15, 2026 at 21:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-476

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: cxl/mce: Make the MCE notifier per-region Flavien Solt reported lifetime issues with the CXL MCE notifier, which can lead to NULL dereferences and use-after-free in the MCE handler. The notifier was registered per memory device and stored in 'struct cxl_memdev_state', even though it only needs the region state (the region's SPA range and its extended linear cache size). Instead of keeping the memory device and endpoint alive, the correct fix is to move the notifier into 'struct cxl_region' and register it from cxl_region_probe() as it should be a per-region notifier. Setup the registration to only happen for regions that have an extended linear cache as that is the only current usage. Remove cxl_port_get_spa_cache_alias() as it is now dead code. [ dj: Update dev_warn() when notifier fails due to kconfig. (Ben) ]
Title cxl/mce: Make the MCE notifier per-region
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:31:07.784Z

Reserved: 2026-09-11T19:38:34.726Z

Link: CVE-2026-89570

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:41.050

Modified: 2026-09-13T07:17:22.967

Link: CVE-2026-89570

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:39Z

Links: CVE-2026-89570 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:00:17Z

Weaknesses