CVE-2024-35939: dma-direct: Leak pages on dma_set_decrypted() failure
Published May 19, 2024
·Updated
dma-direct: Leak pages on dmasetdecrypted() failure
Affected Software
11 affected componentsFixes available
debian/linux<=5.10.223-1, <=5.10.234-1
6.1.129-16.1.133-16.12.22-16.12.25-1
IBM Security Verify Governance<=ISVG 10.0.2
IBM Security Verify Governance - Identity Manager virtual appliance component<=ISVG 10.0.2
redhat/kernel<6.1.86
6.1.86
redhat/kernel<6.6.27
6.6.27
redhat/kernel<6.8.6
6.8.6
redhat/kernel<6.9
6.9
Linux Linux kernel<6.1.86
Linux Linux kernel>=6.2<6.6.27
Linux Linux kernel>=6.7<6.8.6
Microsoft cbl2 kernel 5.15.186.1-1
Remediation
Event History
May 19, 2024
CVE Published
via MITRE·10:10 AM
Data Sourced
via MITRE·10:10 AM
Description
Data Sourced
via NVD·11:15 AM
Description
Data Sourced
via NVD·11:15 AM
RemedySeverityAffected Software
May 20, 2024
Data Sourced
via Red Hat·03:30 PM
DescriptionSeverityAffected Software
Jul 11, 2024
Data Sourced
via Launchpad·07:47 PM
Description
Apr 27, 2025
Data Sourced
via Ubuntu·12:23 AM
RemedyDescriptionSeverityAffected Software
Sep 27, 2025
Data Sourced
via Microsoft·01:01 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·01:01 AM
Affected Software
Updated
via Microsoft·01:01 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-35939?
CVE-2024-35939 is categorized as a medium severity vulnerability in the Linux kernel.
2
How do I fix CVE-2024-35939?
To resolve CVE-2024-35939, update your Linux kernel to version 6.1.86, 6.6.27, 6.8.6, or 6.9, or use the corresponding patched versions in Debian.
3
What systems are affected by CVE-2024-35939?
CVE-2024-35939 affects Linux kernel versions prior to 6.1.86, 6.6.27, 6.8.6, 6.9, and Debian versions up to 5.10.226-1.
4
What types of attacks can exploit CVE-2024-35939?
CVE-2024-35939 can potentially be exploited by an untrusted host, leading to memory management issues.
5
Is CVE-2024-35939 related to memory management in Linux?
Yes, CVE-2024-35939 involves a memory management flaw linked to the dma_set_decrypted function in the Linux kernel.