CVE-2024-35939
A critical flaw in the Linux kernel could let an untrusted host cause memory to be incorrectly marked as shared, potentially exposing sensitive data. The issue arises when certain memory encryption functions fail, leading to leaked pages. The kernel has addressed the problem by changing the handling of failed decryption calls.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel (all versions before the fix) on systems using Intel TDX (Trusted Domain Extensions).
Real-world impact
An attacker with local access could cause the kernel to expose decrypted memory pages, allowing them to read or modify data that should remain confidential, leading to data theft or system compromise.
Why this severity
The CVSS score of 9.3 reflects that the flaw can be exploited locally with no special privileges, and it can compromise confidentiality, integrity, and availability of the system.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the fix for CVE-2024-35939.
NVD description indicates the kernel has resolved the issue.
Timeline
- May 19, 2024 · May 19, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.