CVE-2015-2877

Source
https://cve.org/CVERecord?id=CVE-2015-2877
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2015-2877.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2015-2877
Downstream
Published
2017-03-03T11:59:00Z
Modified
2026-04-10T03:46:15.580574Z
Severity
  • 3.3 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection (CAIN) attack. NOTE: the vendor states "Basically if you care about this attack vector, disable deduplication." Share-until-written approaches for memory conservation among mutually untrusting tenants are inherently detectable for information disclosure, and can be classified as potentially misunderstood behaviors rather than vulnerabilities

Database specific
{
    "isDisputed": true
}
References

Affected packages