cbcvebase.
CVE-2024-35939
published 2024-05-19

CVE-2024-35939: In the Linux kernel, the following vulnerability has been resolved: dma-direct: Leak pages on dma_set_decrypted() failure On TDX it is possible for the…

PriorityP427high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.22%
12.2th percentile
In the Linux kernel, the following vulnerability has been resolved: dma-direct: Leak pages on dma_set_decrypted() failure On TDX it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is returned and the resulting memory is shared. Callers need to take care to handle these errors to avoid returning decrypted (shared) memory to the page allocator, which could lead to functional or security issues. DMA could free decrypted/shared pages if dma_set_decrypted() fails. This should be a rare case. Just leak the pages in this case instead of freeing them.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.90-1 (bookworm)linux 6.1.90-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 5.7.7 < 5.85.8
linuxlinux>= 56fccf21d1961a06e2a0c96ce446ebf036651062 < 4e0cfb25d49da2e6261ad582f58ffa5b5dd8c8e94e0cfb25d49da2e6261ad582f58ffa5b5dd8c8e9
linuxlinux>= 56fccf21d1961a06e2a0c96ce446ebf036651062 < 4031b72ca747a1e6e9ae4fa729e765b43363d66a4031b72ca747a1e6e9ae4fa729e765b43363d66a
linuxlinux>= 56fccf21d1961a06e2a0c96ce446ebf036651062 < b57326c96b7bc7638aa8c44e12afa2defe0c934cb57326c96b7bc7638aa8c44e12afa2defe0c934c
linuxlinux>= 56fccf21d1961a06e2a0c96ce446ebf036651062 < b9fa16949d18e06bdf728a560f5c8af56d2bdcafb9fa16949d18e06bdf728a560f5c8af56d2bdcaf
linuxlinux_kernel< 6.1.866.1.86
linuxlinux_kernel>= 0 < 6.1.90-16.1.90-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.0-38.386.8.0-38.38
linuxlinux_kernel>= 6.2 < 6.6.276.6.27
linuxlinux_kernel>= 6.7 < 6.8.66.8.6
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
cisa9.8CRITICAL
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_msrc5.5MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.