Vulnary
← back to the feed
Critical· 9.3official fix available

CVE-2024-36909

A flaw in the Linux kernel's VMBus driver allows a malicious host to cause memory intended to be encrypted to remain shared and unencrypted. This occurs when certain memory encryption functions fail during the handling of ring buffers.

publishedMay 30, 2024
last modifiedAug 4, 2026
sourcesNVD
severity · cvss
9.3
critical · how bad it is
exploitation · epss
<1%
13th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 4, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Users running Linux kernel version 6.9 or affected versions in CoCo (Confidential Computing) Virtual Machines.

02

Real-world impact

An untrusted host could access sensitive data by forcing the system to use unencrypted, shared memory instead of the intended encrypted memory.

03

Why this severity

The critical score reflects that an attacker can achieve a total loss of confidentiality, integrity, and availability by exploiting the way memory is handled in CoCo VMs.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade the Linux kernel to a version that includes the fix for the hv: vmbus driver.

NVD-referenced vendor advisory

05

Timeline

  1. May 30, 2024 · May 30, 2024
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Aug 4, 2026 · 2d ago
    Advisory updated
    The NVD record was last revised.
  3. Aug 5, 2026 · 1d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorLocal
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeChanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →