CVE-2024-36913Exposure of Sensitive System Information Due to Uncleared Debug Information in Linux

Severity
8.1HIGHNVD
OSV6.5
EPSS
0.0%
top 87.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 30
Latest updateAug 13

Description

In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is returned and the resulting memory is shared. Callers need to take care to handle these errors to avoid returning decrypted (shared) memory to the page allocator, which could lead to functional or security issues. VMBus code coul

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages7 packages

NVDlinux/linux_kernel5.166.1.143+3
Debianlinux/linux_kernel< 6.1.147-1+2
Ubuntulinux/linux_kernel< 6.8.0-40.40
CVEListV5linux/linuxf2f136c05fb6093818a3b3fefcba46231ac66a627f2afcbfe4f6b6047b5f68db5067b7321e5be125+4
debiandebian/linux< linux 6.1.147-1 (bookworm)

Also affects: Debian Linux 11.0

Patches

🔴Vulnerability Details

6
OSV
linux-lowlatency, linux-raspi vulnerabilities2024-08-13
OSV
linux-azure vulnerabilities2024-08-13
OSV
linux-oem-6.8 vulnerabilities2024-08-12
OSV
linux-nvidia-lowlatency, linux-oracle vulnerabilities2024-08-09
OSV
linux, linux-aws, linux-gcp, linux-gke, linux-ibm, linux-nvidia, linux-nvidia-6.8 vulnerabilities2024-08-08

📋Vendor Advisories

7
Ubuntu
Linux kernel vulnerabilities2024-08-13
Ubuntu
Linux kernel (OEM) vulnerabilities2024-08-12
Ubuntu
Linux kernel vulnerabilities2024-08-09
Ubuntu
Linux kernel vulnerabilities2024-08-08
Red Hat
kernel: Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails2024-05-30

💬Community

1
Bugzilla
CVE-2024-36913 kernel: Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails2024-06-03