CVE-2024-36913
A critical flaw in the Linux kernel’s Hyper-V VMBus driver can leak memory pages when the host fails to encrypt or decrypt memory. The bug allows an attacker to cause the kernel to share decrypted memory with the page allocator, potentially exposing data or disrupting system operation. It affects recent kernel releases, including Linux 6.9 and Debian 11.0.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Linux kernel (v6.9 and newer) and Debian Linux 11.0 users running the Hyper‑V VMBus driver.
Real-world impact
An attacker could trigger the failure, causing sensitive memory to be leaked to other processes or the host, leading to data exposure or a denial‑of‑service condition.
Why this severity
The CVSS score of 9.3 reflects local access with no authentication, no user interaction, and complete compromise of confidentiality, integrity, and availability. The vector shows that the vulnerability is exploitable from the host side, requires low effort, and can fully compromise the system.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- May 30, 2024 · May 30, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.