PT-2017-1614 · Linux+2 · Linux Kernel+2
Antonio Barresi
+3
·
Publicado
2017-03-02
·
Atualizado
2024-08-06
·
CVE-2015-2877
CVSS v3.1
3.3
Baixa
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 2.6.32 through 4.x
Description
The issue is related to the Kernel Samepage Merging (KSM) component in the Linux kernel, which does not prevent the use of a write-timing side channel. This allows guest OS users to defeat the Address Space Layout Randomization (ASLR) protection mechanism on other guest OS instances via a Cross-VM ASL Introspection (CAIN) attack. The vendor suggests disabling deduplication to mitigate this attack vector. This issue can be classified as a potentially misunderstood behavior rather than a vulnerability, as share-until-written approaches for memory conservation among mutually untrusting tenants are inherently detectable for information disclosure.
Recommendations
For Linux kernel versions 2.6.32 through 4.x, consider disabling deduplication to mitigate the risk of exploitation. As a temporary workaround, restrict the use of the Kernel Samepage Merging (KSM) component until a more comprehensive solution is available.
Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Debian
Linux Kernel