boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2024-57793MEDIUM
Linux Linux — virt: tdx-guest: Just leak decrypted memory on unrecoverable errors
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  N  N    5.5   .0020   10.5     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    f4738f56d1dc62aaba69b33702a5ab098f1b8c63 –  —
  Linux    6.7 –                                       6.12.8
TIMELINE
  Jan 11  Reserved by Linux
  Jan 11  Published (CNA: Linux)
  Aug 4   RESCORED — CVE-2024-57793 (Linux). CVSS 9.3 → 5.5 (NVD).
CWE-401 · CNA: Linux · CVSS v3.1 · 2 references · NVD status: Modified

Description

In the Linux kernel, the following vulnerability has been resolved: virt: tdx-guest: Just leak decrypted memory on unrecoverable errors In CoCo VMs it is possible for the untrusted host to cause set_memory_decrypted() to fail such that an error is returned and the resulting memory is shared. Callers need to take care to handle these errors to avoid returning decrypted (shared) memory to the page allocator, which could lead to functional or security issues. Leak the decrypted memory when set_memory_decrypted() fails, and don't need to print an error since set_memory_decrypted() will call WARN_ONCE().

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
January 11, 2025ReservedReserved by Linux
January 11, 2025PublishedPublished (CNA: Linux)
August 4, 2026RESCOREDRESCORED — CVE-2024-57793 (Linux). CVSS 9.3 → 5.5 (NVD).

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
LinuxLinuxf4738f56d1dc62aaba69b33702a5ab098f1b8c63
LinuxLinux6.76.12.8

Weaknesses

CWE-401

References (2)

Related

Authoritative record: CVE-2024-57793 at cve.org

Vendors: linux

Weaknesses: CWE-401

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-57793 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.