PT-2024-27204 · Linux+5 · Linux Kernel+5

·

CVE-2024-36913

·

Published

2024-04-10

·

Updated

2026-05-26

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.37
Description The issue arises in CoCo VMs where an untrusted host can cause set memory encrypted() or set memory decrypted() to fail, leading to shared memory. Callers must handle these errors to prevent returning decrypted memory to the page allocator, which could result in functional or security issues. The VMBus code may free decrypted pages if set memory encrypted() or set memory decrypted() fails, potentially leaking pages.
Recommendations Update to Linux kernel version 6.6.37 or later to resolve the issue. As a temporary workaround, consider implementing error handling for set memory encrypted() and set memory decrypted() failures to prevent decrypted memory from being returned to the page allocator. Restrict access to the VMBus code to minimize the risk of exploitation until a patch is applied.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07455
CVE-2024-36913
DLA-4328-1
DSA-5973-1
ECHO-4561-F8D3-6AF0
MGASA-2024-0263
MGASA-2024-0266
OESA-2024-2296
OPENSUSE-SU-2024_2947-1
SUSE-SU-2024:2802-1
SUSE-SU-2024:2894-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2947-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6949-1
USN-6949-2
USN-6952-1
USN-6952-2
USN-6955-1

Affected Products

Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu