{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-36913","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-05-30T15:25:07.067Z","datePublished":"2024-05-30T15:29:11.016Z","dateUpdated":"2026-08-05T11:32:00.757Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:32:00.757Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nDrivers: hv: vmbus: Leak pages if set_memory_encrypted() fails\n\nIn CoCo VMs it is possible for the untrusted host to cause\nset_memory_encrypted() or set_memory_decrypted() to fail such that an\nerror is returned and the resulting memory is shared. Callers need to\ntake care to handle these errors to avoid returning decrypted (shared)\nmemory to the page allocator, which could lead to functional or security\nissues.\n\nVMBus code could free decrypted pages if set_memory_encrypted()/decrypted()\nfails. Leak the pages if this happens."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":9.3,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:L - The attacker is the untrusted Hyper-V host/VMM, which reaches the vulnerable code through the paravirtual page-conversion interface (TDVMCALL<MapGPA> for TDX, GHCB Page State Change for SEV-SNP) of the guest it hosts, not via any network stack. This matches the established scoring for CoCo host-to-guest issues in this subsystem (CVE-2024-57793).\nAC:L - The VMM implements the page-state-change handler invoked by `enc_status_change_prepare`/`_finish` and can deterministically fail it every time, forcing `set_memory_decrypted()`/`set_memory_encrypted()` to return an error on demand. No race, timing, or memory-layout condition outside the attacker's control is involved.\nPR:N - `vmbus_connect()` runs from `vmbus_bus_init()` during guest boot and `vmbus_disconnect()` from module unload/kexec, so the host needs no account, credential, or capability inside the guest at all. The hypervisor sits entirely outside the guest's authentication domain in the SEV-SNP/TDX threat model.\nUI:N - The vulnerable path executes automatically when the hv_vmbus driver initializes at guest boot; the host triggers the failed conversion itself and no guest user or administrator has to perform any action.\nS:C - Returning still-shared pages to the buddy allocator breaks the hardware-enforced SEV-SNP/TDX confidential-computing boundary, so data belonging to every other authority in the guest (all processes, containers, and the guest's protected TCB) becomes host-accessible — impact far beyond the VMBus driver's own scope, directly analogous to an IOMMU/DMA boundary bypass.\nC:H - The recycled monitor pages remain mapped shared by the host, so anything the guest later places in them — slab objects, page cache, anonymous user data, cryptographic keys — is exposed in plaintext, giving a persistent, continuously refreshed arbitrary-read window into confidential guest memory.\nI:H - The host can write those pages at will while they hold live kernel or user data, yielding an arbitrary-write primitive into whatever object currently occupies them (kernel structures with function pointers or list heads), which is leverageable for control-flow hijack inside the guest.\nA:H - Host modification of live kernel objects in the recycled pages, together with the private/shared state mismatch left by the aborted conversion (#VE / EPT violation on subsequent guest kernel accesses), reliably produces guest memory corruption and kernel panic."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/hv/connection.c"],"versions":[{"version":"f2f136c05fb6093818a3b3fefcba46231ac66a62","lessThan":"7f2afcbfe4f6b6047b5f68db5067b7321e5be125","status":"affected","versionType":"git"},{"version":"f2f136c05fb6093818a3b3fefcba46231ac66a62","lessThan":"6123a4e8e25bd40cf44db14694abac00e6b664e6","status":"affected","versionType":"git"},{"version":"f2f136c05fb6093818a3b3fefcba46231ac66a62","lessThan":"e813a0fc2e597146e9cebea61ced9c796d4e308f","status":"affected","versionType":"git"},{"version":"f2f136c05fb6093818a3b3fefcba46231ac66a62","lessThan":"03f5a999adba062456c8c818a683beb1b498983a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/hv/connection.c"],"versions":[{"version":"5.16","status":"affected"},{"version":"0","lessThan":"5.16","status":"unaffected","versionType":"semver"},{"version":"6.1.143","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.31","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.8.10","lessThanOrEqual":"6.8.*","status":"unaffected","versionType":"semver"},{"version":"6.9","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16","versionEndExcluding":"6.1.143"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16","versionEndExcluding":"6.6.31"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16","versionEndExcluding":"6.8.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16","versionEndExcluding":"6.9"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/7f2afcbfe4f6b6047b5f68db5067b7321e5be125"},{"url":"https://git.kernel.org/stable/c/6123a4e8e25bd40cf44db14694abac00e6b664e6"},{"url":"https://git.kernel.org/stable/c/e813a0fc2e597146e9cebea61ced9c796d4e308f"},{"url":"https://git.kernel.org/stable/c/03f5a999adba062456c8c818a683beb1b498983a"}],"title":"Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-1258","lang":"en","description":"CWE-1258 Exposure of Sensitive System Information Due to Uncleared Debug Information"}]}],"affected":[{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","versions":[{"version":"1da177e4c3f4","status":"affected","lessThan":"6123a4e8e25b","versionType":"custom"},{"version":"1da177e4c3f4","status":"affected","lessThan":"e813a0fc2e59","versionType":"custom"},{"version":"1da177e4c3f4","status":"affected","lessThan":"03f5a999adba","versionType":"custom"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":8.1,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","integrityImpact":"HIGH","userInteraction":"NONE","attackComplexity":"HIGH","availabilityImpact":"HIGH","privilegesRequired":"NONE","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2024-06-05T14:31:38.077186Z","id":"CVE-2024-36913","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-05T14:41:56.102Z"}},{"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/6123a4e8e25bd40cf44db14694abac00e6b664e6","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/e813a0fc2e597146e9cebea61ced9c796d4e308f","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/03f5a999adba062456c8c818a683beb1b498983a","tags":["x_transferred"]},{"url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2025-11-03T17:31:16.014Z"}}]}}