Answer in brief
CVE-2024-35791 records a Unknown severity vulnerability in KVM: SVM: Flush pages under kvm->lock to fix UAF in svm_register_enc_region(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2024-35791 records a Unknown severity vulnerability in KVM: SVM: Flush pages under kvm->lock to fix UAF in svm_register_enc_region(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4f627ecde7329e476a077bb0590db8f27bb8f912 <2d13b79640b147bd77c34a5998533b2021a4122d || >=19a23da53932bc8011220bd8c410cb76012de004 <e126b508ed2e616d679d85fca2fbe77bb48bbdd7 || >=19a23da53932bc8011220bd8c410cb76012de004 <4868c0ecdb6cfde7c70cf478c46e06bb9c7e5865 || >=19a23da53932bc8011220bd8c410cb76012de004 <12f8e32a5a389a5d58afc67728c76e61beee1ad4 || >=19a23da53932bc8011220bd8c410cb76012de004 <f6d53d8a2617dd58c89171a6b9610c470ebda38a || >=19a23da53932bc8011220bd8c410cb76012de004 <5ef1d8c1ddbf696e47b226e11888eaf8d9e8e807 || f1ecde00ce1694597f923f0d25f7a797c5243d99 || 848bcb0a1d96f67d075465667d3a1ad4af56311e || >=5.10.15 <5.10.215 || >=4.19.176 <4.20 || >=5.4.98 <5.5 | 2d13b79640b147bd77c34a5998533b2021a4122d, e126b508ed2e616d679d85fca2fbe77bb48bbdd7, 4868c0ecdb6cfde7c70cf478c46e06bb9c7e5865, 12f8e32a5a389a5d58afc67728c76e61beee1ad4, f6d53d8a2617dd58c89171a6b9610c470ebda38a, 5ef1d8c1ddbf696e47b226e11888eaf8d9e8e807, 5.10.215, 4.20, 5.5 |
| Linux/Linuxgeneric | 5.11 | Not reported |
Published upstream
May 17, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Flush pages under kvm->lock to fix UAF in svm_register_enc_region() Do the cache flush of converted pages in svm_register_enc_region() before dropping kvm->lock to fix use-after-free issues where region and/or its array of pages could be freed by a different task, e.g. if userspace has __unregister_enc_region_locked() already queued up for the region. Note, the "obvious" alternative of using local variables doesn't fully resolve the bug, as region->pages is also dynamically allocated. I.e. the region structure itself would be fine, but region->pages could be freed. Flushing multiple pages under kvm->lock is unfortunate, but the entire flow is a rare slow path, and the manual flush is only needed on CPUs that lack coherency for encrypted memory.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4f627ecde7329e476a077bb0590db8f27bb8f912 <2d13b79640b147bd77c34a5998533b2021a4122d || >=19a23da53932bc8011220bd8c410cb76012de004 <e126b508ed2e616d679d85fca2fbe77bb48bbdd7 || >=19a23da53932bc8011220bd8c410cb76012de004 <4868c0ecdb6cfde7c70cf478c46e06bb9c7e5865 || >=19a23da53932bc8011220bd8c410cb76012de004 <12f8e32a5a389a5d58afc67728c76e61beee1ad4 || >=19a23da53932bc8011220bd8c410cb76012de004 <f6d53d8a2617dd58c89171a6b9610c470ebda38a || >=19a23da53932bc8011220bd8c410cb76012de004 <5ef1d8c1ddbf696e47b226e11888eaf8d9e8e807 || f1ecde00ce1694597f923f0d25f7a797c5243d99 || 848bcb0a1d96f67d075465667d3a1ad4af56311e || >=5.10.15 <5.10.215 || >=4.19.176 <4.20 || >=5.4.98 <5.5 | 2d13b79640b147bd77c34a5998533b2021a4122d, e126b508ed2e616d679d85fca2fbe77bb48bbdd7, 4868c0ecdb6cfde7c70cf478c46e06bb9c7e5865, 12f8e32a5a389a5d58afc67728c76e61beee1ad4, f6d53d8a2617dd58c89171a6b9610c470ebda38a, 5ef1d8c1ddbf696e47b226e11888eaf8d9e8e807, 5.10.215, 4.20, 5.5 |
| Linux/Linuxgeneric | 5.11 | Not reported |
Published upstream
May 17, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Flush pages under kvm->lock to fix UAF in svm_register_enc_region() Do the cache flush of converted pages in svm_register_enc_region() before dropping kvm->lock to fix use-after-free issues where region and/or its array of pages could be freed by a different task, e.g. if userspace has __unregister_enc_region_locked() already queued up for the region. Note, the "obvious" alternative of using local variables doesn't fully resolve the bug, as region->pages is also dynamically allocated. I.e. the region structure itself would be fine, but region->pages could be freed. Flushing multiple pages under kvm->lock is unfortunate, but the entire flow is a rare slow path, and the manual flush is only needed on CPUs that lack coherency for encrypted memory.
Quoted source text, attributed separately from HOL analysis.