CVE-2024-36912·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Track decrypted status in vmbus_gpadl In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is returned and the resulting memory is shared. Callers need to take care to handle these errors to avoid returning decrypted (shared) memory to the page allocator, which could lead to functional or security issues. In order to make sure callers of vmbus_establish_gpadl() and vmbus_teardown_gpadl() don't return decrypted/shared pages to allocators, add a field in struct vmbus_gpadl to keep track of the decryption status of the buffers. This will allow the callers to know if they should free or leak the pages.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.8.10
- Published
- 2024-05-30
Affected versions
From: 6.7
Until: 6.8.10
Fixed in: 6.8.10
How to fix this CVE
Update your Linux kernel to version 6.8.10 or later to resolve this memory encryption tracking vulnerability affecting confidential computing environments. This fix ensures that the vmbus_gpadl structure properly tracks decryption status, preventing shared memory pages from being incorrectly returned to allocators in CoCo VMs. Organizations running kernel versions 6.7 through 6.8.9 should prioritize patching to mitigate potential memory corruption and security issues.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Check kernel version with: uname -r — confirm it is 6.8.10 or later, or earlier than 6.7
- Verify vmbus module is loaded: lsmod | grep hv_vmbus — this indicates Hyper-V integration and potential exposure
- Search kernel logs for decryption failures: sudo grep -i 'set_memory_encrypted\|set_memory_decrypted' /var/log/kern.log or dmesg output
- Confirm patch application by checking kernel config: grep CONFIG_HYPERV /boot/config-$(uname -r) and verifying kernel build date is post-fix release
FAQ
What is CVE-2024-36912?
CVE-2024-36912 is a memory encryption tracking vulnerability in the Linux kernel's Hyper-V vmbus driver that affects confidential computing virtual machines. When encryption/decryption operations fail, the kernel may return shared memory pages to allocators without proper tracking, leading to memory corruption or information disclosure.
Is CVE-2024-36912 being actively exploited?
No, CVE-2024-36912 is not currently listed on the CISA KEV catalog and has no known public exploits available. However, it poses a real risk in CoCo VM environments where an untrusted host could trigger the vulnerability.
What versions of Kernel are affected by CVE-2024-36912?
Linux kernel versions 6.7 through 6.8.10 (inclusive) are affected. The vulnerability was fixed in 6.8.10 and later stable releases.
How do I check if my server is vulnerable to CVE-2024-36912?
Run uname -r to check your kernel version. If the output shows a version between 6.7 and 6.8.10, and you are running Hyper-V integration (verify with lsmod | grep hv_vmbus), your system is vulnerable.
Does Defensia detect CVE-2024-36912?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2024-36912 will appear in your dashboard with remediation steps and affected version ranges.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/1999644d95194d4a58d3e80ad04ce19220a01a81
- https://git.kernel.org/stable/c/211f514ebf1ef5de37b1cf6df9d28a56cfd242ca
- https://git.kernel.org/stable/c/8e62341f5c45b27519b7d193bcc32ada416ad9d8
- https://git.kernel.org/stable/c/bfae56be077ba14311509e70706a13458f87ea99
- https://git.kernel.org/stable/c/1999644d95194d4a58d3e80ad04ce19220a01a81
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-36912. Free for 1 server.
Get started free