cbcvebase.
CVE-2024-35791
published 2024-05-17

CVE-2024-35791: In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Flush pages under kvm->lock to fix UAF in svm_register_enc_region() Do the cache…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.0th percentile
In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Flush pages under kvm->lock to fix UAF in svm_register_enc_region() Do the cache flush of converted pages in svm_register_enc_region() before dropping kvm->lock to fix use-after-free issues where region and/or its array of pages could be freed by a different task, e.g. if userspace has __unregister_enc_region_locked() already queued up for the region. Note, the "obvious" alternative of using local variables doesn't fully resolve the bug, as region->pages is also dynamically allocated. I.e. the region structure itself would be fine, but region->pages could be freed. Flushing multiple pages under kvm->lock is unfortunate, but the entire flow is a rare slow path, and the manual flush is only needed on CPUs that lack coherency for encrypted memory.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 19a23da53932bc8011220bd8c410cb76012de004 < e126b508ed2e616d679d85fca2fbe77bb48bbdd7e126b508ed2e616d679d85fca2fbe77bb48bbdd7
linuxlinux>= 19a23da53932bc8011220bd8c410cb76012de004 < 4868c0ecdb6cfde7c70cf478c46e06bb9c7e58654868c0ecdb6cfde7c70cf478c46e06bb9c7e5865
linuxlinux>= 19a23da53932bc8011220bd8c410cb76012de004 < 12f8e32a5a389a5d58afc67728c76e61beee1ad412f8e32a5a389a5d58afc67728c76e61beee1ad4
linuxlinux>= 19a23da53932bc8011220bd8c410cb76012de004 < f6d53d8a2617dd58c89171a6b9610c470ebda38af6d53d8a2617dd58c89171a6b9610c470ebda38a
linuxlinux>= 19a23da53932bc8011220bd8c410cb76012de004 < 5ef1d8c1ddbf696e47b226e11888eaf8d9e8e8075ef1d8c1ddbf696e47b226e11888eaf8d9e8e807
linuxlinux>= 4.19.176 < 4.204.20
linuxlinux>= 4f627ecde7329e476a077bb0590db8f27bb8f912 < 2d13b79640b147bd77c34a5998533b2021a4122d2d13b79640b147bd77c34a5998533b2021a4122d
linuxlinux>= 5.10.15 < 5.10.2155.10.215
linuxlinux>= 5.4.98 < 5.55.5
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 4.19.176 < 4.204.20
linuxlinux_kernel>= 5.10.15 < 5.10.2155.10.215
linuxlinux_kernel>= 5.11.1 < 5.15.1545.15.154
linuxlinux_kernel>= 5.16 < 6.1.846.1.84

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.