First published: Tue Feb 25 2020(Updated: )
NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.
Credit: chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Native Client | =2015 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0565 is considered a high-severity vulnerability due to its potential to facilitate Rowhammer attacks.
CVE-2015-0565 specifically affects Google Native Client version 2015.
To mitigate CVE-2015-0565, ensure that you update to the latest version of Google Native Client that addresses this vulnerability.
Rowhammer attacks exploit the physical properties of DRAM to manipulate memory without direct access, enabled by the CLFLUSH instruction in CVE-2015-0565.
Exploiting CVE-2015-0565 can potentially allow an attacker to gain unauthorized access to sensitive data or escalate privileges on affected systems.