CVE-2015-2877: Infoleak
DISPUTED Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection (CAIN) attack. NOTE: the vendor states "Basically if you care about this attack vector, disable deduplication." Share-until-written approaches for memory conservation among mutually untrusting tenants are inherently detectable for information disclosure, and can be classified as potentially misunderstood behaviors rather than vulnerabilities.
Other sources
Antonio Barresi reports:
We discovered a new attack vector against memory deduplication in Virtual Machine Monitors (VMM) where attackers can effectively leak randomized base addresses of libraries and executables in processes of neighboring Virtual Machines (VM).
The details are described in the security advisory below and in our WOOT'15 paper: https://www.usenix.org/conference/woot15/workshop-program/presentation/barresi
Several vendors were notified about this issue in the beginning of June. This issue has CVE-2015-2877 assigned.
An overview can also be found here: http://www.antoniobarresi.com/security/cloud/2015/07/30/cain/
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2877?
The severity of CVE-2015-2877 is considered medium due to its potential impact on ASLR protection in virtualized environments.
How do I fix CVE-2015-2877?
To address CVE-2015-2877, it is recommended to apply the latest patches or updates to the Linux kernel that mitigate the vulnerability.
What is the impact of CVE-2015-2877?
CVE-2015-2877 allows a guest operating system to exploit a timing side channel to bypass Address Space Layout Randomization (ASLR) protections on other guest OS instances.
Which versions of Linux kernel are affected by CVE-2015-2877?
CVE-2015-2877 affects Linux kernel versions from 2.6.32 through 4.x up to 4.20.15.
Is Red Hat Enterprise Linux vulnerable to CVE-2015-2877?
Yes, Red Hat Enterprise Linux versions 4.0, 5.0, 6.0, and 7.0 are vulnerable to CVE-2015-2877.