{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-36909","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-05-30T15:25:07.067Z","datePublished":"2024-05-30T15:29:08.339Z","dateUpdated":"2026-08-05T11:31:56.472Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:31:56.472Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nDrivers: hv: vmbus: Don't free ring buffers that couldn't be re-encrypted\n\nIn CoCo VMs it is possible for the untrusted host to cause\nset_memory_encrypted() or set_memory_decrypted() to fail such that an\nerror is returned and the resulting memory is shared. Callers need to\ntake care to handle these errors to avoid returning decrypted (shared)\nmemory to the page allocator, which could lead to functional or security\nissues.\n\nThe VMBus ring buffer code could free decrypted/shared pages if\nset_memory_decrypted() fails. Check the decrypted field in the struct\nvmbus_gpadl for the ring buffers to decide whether to free the memory."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":9.3,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:L - The attacker is the untrusted Hyper-V host/VMM of a confidential guest, reaching the vulnerable code through the paravirtual VMBus interface (GPADL creation status, channel rescind, and the host-visibility/page-state-change hypercalls backing set_memory_encrypted()), not through any network stack. This is a local, non-network attack channel against the guest kernel, consistent with the scoring of the sibling CoCo VMBus issues.\nAC:L - The host implements the page-conversion handler and can fail set_memory_encrypted()/set_memory_decrypted() on demand every time, while independently forcing the vmbus_open()/teardown error paths via GPADL creation status, OPENCHANNEL failure or channel rescind. No race, timing window, or memory layout outside the attacker's control is involved, and the sequence is repeatable to seed many shared pages.\nPR:N - Privileges are measured against the vulnerable component — the guest kernel — and in the SEV-SNP/TDX threat model the hypervisor holds no account, credential, or capability inside the guest and sits entirely outside its authentication domain. The affected paths run automatically from driver probe/remove and channel open/close, requiring nothing from the host but its normal VMBus role.\nUI:N - The vulnerable paths execute automatically when hv_vmbus devices are probed, opened, rescinded or removed, and the host initiates the failing conversion and the teardown itself. No guest user or administrator action is required.\nS:C - Returning still-decrypted pages to the buddy allocator voids the hardware-enforced SEV-SNP/TDX memory-confidentiality boundary — a protection managed by the CPU firmware/RMP, not by the guest kernel — for memory subsequently owned by every other authority in the guest (all processes, containers, and the guest TCB). This is directly analogous to an IOMMU/DMA boundary bypass, where impact extends well beyond the VMBus driver's own security scope.\nC:H - Megabytes of ring-buffer pages that remain mapped shared to the host are recycled by the page allocator for arbitrary kernel and user allocations — slab objects, page cache, anonymous user pages, page tables, cryptographic keys — giving the host a persistent, continuously refreshed plaintext read window into confidential guest memory. That is a total break of the confidential VM's core confidentiality guarantee.\nI:H - The same recycled pages remain host-writable, so the host obtains an arbitrary-write primitive into whatever live kernel object currently occupies them (credentials, page tables, structures holding function pointers or list heads), which is leverageable for full control-flow hijack and kernel compromise inside the guest.\nA:H - Host writes into live kernel data occupying the recycled pages, combined with the private/shared encryption-state mismatch left by the aborted conversion (#VE / EPT violations or ciphertext garbage on subsequent private accesses), reliably produces guest memory corruption and kernel panic."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/hv/channel.c"],"versions":[{"version":"d4dccf353db80e209f262e3973c834e6e48ba9a9","lessThan":"2f622008bf784a9f5dd17baa19223cc2ac30a039","status":"affected","versionType":"git"},{"version":"d4dccf353db80e209f262e3973c834e6e48ba9a9","lessThan":"82f9e213b124a7d2bb5b16ea35d570260ef467e0","status":"affected","versionType":"git"},{"version":"d4dccf353db80e209f262e3973c834e6e48ba9a9","lessThan":"a9212a4e2963a7fbe3864ba33dc551d4ad8d0abb","status":"affected","versionType":"git"},{"version":"d4dccf353db80e209f262e3973c834e6e48ba9a9","lessThan":"30d18df6567be09c1433e81993e35e3da573ac48","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/hv/channel.c"],"versions":[{"version":"5.16","status":"affected"},{"version":"0","lessThan":"5.16","status":"unaffected","versionType":"semver"},{"version":"6.1.91","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.31","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.8.10","lessThanOrEqual":"6.8.*","status":"unaffected","versionType":"semver"},{"version":"6.9","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16","versionEndExcluding":"6.1.91"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16","versionEndExcluding":"6.6.31"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16","versionEndExcluding":"6.8.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16","versionEndExcluding":"6.9"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/2f622008bf784a9f5dd17baa19223cc2ac30a039"},{"url":"https://git.kernel.org/stable/c/82f9e213b124a7d2bb5b16ea35d570260ef467e0"},{"url":"https://git.kernel.org/stable/c/a9212a4e2963a7fbe3864ba33dc551d4ad8d0abb"},{"url":"https://git.kernel.org/stable/c/30d18df6567be09c1433e81993e35e3da573ac48"}],"title":"Drivers: hv: vmbus: Don't free ring buffers that couldn't be re-encrypted","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-06-06T18:33:37.652556Z","id":"CVE-2024-36909","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-07-24T15:25:16.529Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T03:43:50.141Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/2f622008bf784a9f5dd17baa19223cc2ac30a039","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/82f9e213b124a7d2bb5b16ea35d570260ef467e0","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/a9212a4e2963a7fbe3864ba33dc551d4ad8d0abb","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/30d18df6567be09c1433e81993e35e3da573ac48","tags":["x_transferred"]}]}]}}