CVE-2015-2877
published 2017-03-03CVE-2015-2877: Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat…
PriorityP412low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.94%
57.0th percentile
Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection (CAIN) attack. NOTE: the vendor states "Basically if you care about this attack vector, disable deduplication." Share-until-written approaches for memory conservation among mutually untrusting tenants are inherently detectable for information disclosure, and can be classified as potentially misunderstood behaviors rather than vulnerabilities
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | — | — |
| linux | linux_kernel | 2.6.32 – 4.20.15 | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4pm5-34cf-2v36: ** DISPUTED ** Kernel Samepage Merging (KSM) in the Linux kernel 2
ghsa_unreviewed·2022-05-13
CVE-2015-2877 [LOW] CWE-200 GHSA-4pm5-34cf-2v36: ** DISPUTED ** Kernel Samepage Merging (KSM) in the Linux kernel 2
** DISPUTED ** Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection (CAIN) attack. NOTE: the vendor states "Basically if you care about this attack vector, disable deduplication." Share-until-written approaches for memory conservation among mutually untrusting tenants are inherently detectable for information disclosure, and can be classified as potentially misunderstood behaviors rather than vulnerabilities.
OSV
CVE-2015-2877: ** DISPUTED ** Kernel Samepage Merging (KSM) in the Linux kernel 2
osv·2017-03-03·CVSS 3.3
CVE-2015-2877 [LOW] CVE-2015-2877: ** DISPUTED ** Kernel Samepage Merging (KSM) in the Linux kernel 2
** DISPUTED ** Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection (CAIN) attack. NOTE: the vendor states "Basically if you care about this attack vector, disable deduplication." Share-until-written approaches for memory conservation among mutually untrusting tenants are inherently detectable for information disclosure, and can be classified as potentially misunderstood behaviors rather than vulnerabilities.
OSV
CVE-2015-2877: Kernel Samepage Merging (KSM) in the Linux kernel 2
osv·2017-03-03·CVSS 3.3
CVE-2015-2877 [LOW] CVE-2015-2877: Kernel Samepage Merging (KSM) in the Linux kernel 2
Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection (CAIN) attack. NOTE: the vendor states "Basically if you care about this attack vector, disable deduplication." Share-until-written approaches for memory conservation among mutually untrusting tenants are inherently detectable for information disclosure, and can be classified as potentially misunderstood behaviors rather than vulnerabilities
Red Hat
Kernel: Cross-VM ASL INtrospection (CAIN)
vendor_redhat·2015-08-05·CVSS 3.3
CVE-2015-2877 [LOW] Kernel: Cross-VM ASL INtrospection (CAIN)
Kernel: Cross-VM ASL INtrospection (CAIN)
Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection (CAIN) attack. NOTE: the vendor states "Basically if you care about this attack vector, disable deduplication." Share-until-written approaches for memory conservation among mutually untrusting tenants are inherently detectable for information disclosure, and can be classified as potentially misunderstood behaviors rather than vulnerabilities
Statement: This issue affects the versions of the Linux Kernel as shipped with Red Hat Enterprise Linux 4, 5, 6 and 7. Red Hat Product Security has rated this is
Debian
CVE-2015-2877: linux - Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not pr...
vendor_debian·2015·CVSS 3.3
CVE-2015-2877 [LOW] CVE-2015-2877: linux - Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not pr...
Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection (CAIN) attack. NOTE: the vendor states "Basically if you care about this attack vector, disable deduplication." Share-until-written approaches for memory conservation among mutually untrusting tenants are inherently detectable for information disclosure, and can be classified as potentially misunderstood behaviors rather than vulnerabilities
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Unit42
Making Containers More Isolated: An Overview of Sandboxed Container Technologies
blogs_unit42·2019-06-06
Making Containers More Isolated: An Overview of Sandboxed Container Technologies
Threat Research Center
Threat Research
Cloud Cybersecurity Research
## Making Containers More Isolated: An Overview of Sandboxed Container Technologies
Jay Chen
Published: June 6, 2019
Cloud Cybersecurity Research
Learning Hub
Threat Research
Containers
Docker
Kubernetes
LXC
Public cloud
Rkt
Executive Summary
While the majority of the IT industry is in the midst of adopting container-based infrastructure (cloud-native solution), it is imperative to understand the technology’s limitations. Traditional containers such as Docker, Linux Containers (LXC), and Rocket (rkt) are not truly sandboxed as they share the host OS kernel. They are resource-efficient, but the attack surface and the potential impact of a breach are still large, especially in a multi-tenant cloud environme
Unit42
Making Containers More Isolated: An Overview of Sandboxed Container Technologies
blogs_unit42·2019-06-06
Making Containers More Isolated: An Overview of Sandboxed Container Technologies
Executive Summary
While the majority of the IT industry is in the midst of adopting container-based infrastructure (cloud-native solution), it is imperative to understand the technology’s limitations. Traditional containers such as Docker, Linux Containers (LXC), and Rocket (rkt) are not truly sandboxed as they share the host OS kernel. They are resource-efficient, but the attack surface and the potential impact of a breach are still large, especially in a multi-tenant cloud environment that co-locate containers belonging to different customers. The root of the problem is the weak separation between containers when the host OS creates a virtualized userland for each container. There has been research and development focusing on designing truly sandboxed containers. Most of the solutions r
Bugzilla
CVE-2015-2877 Kernel: Cross-VM ASL INtrospection (CAIN)
bugzilla·2015-08-10·CVSS 3.3
CVE-2015-2877 [LOW] CVE-2015-2877 Kernel: Cross-VM ASL INtrospection (CAIN)
CVE-2015-2877 Kernel: Cross-VM ASL INtrospection (CAIN)
Antonio Barresi reports:
We discovered a new attack vector against memory deduplication in
Virtual Machine Monitors (VMM) where attackers can effectively leak
randomized base addresses of libraries and executables in processes
of neighboring Virtual Machines (VM).
The details are described in the security advisory below and in our
WOOT'15 paper:
https://www.usenix.org/conference/woot15/workshop-program/presentation/barresi
Several vendors were notified about this issue in the beginning of
June. This issue has CVE-2015-2877 assigned.
An overview can also be found here:
http://www.antoniobarresi.com/security/cloud/2015/07/30/cain/
Discussion:
There are four suggested workarounds for this issue. Please note that several have a pot
http://www.antoniobarresi.com/files/cain_advisory.txthttp://www.kb.cert.org/vuls/id/935424http://www.securityfocus.com/bid/76256https://bugzilla.redhat.com/show_bug.cgi?id=1252096https://www.kb.cert.org/vuls/id/BGAR-A2CNKGhttps://www.kb.cert.org/vuls/id/BLUU-9ZAHZHhttps://www.usenix.org/system/files/conference/woot15/woot15-paper-barresi.pdfhttp://www.antoniobarresi.com/files/cain_advisory.txthttp://www.kb.cert.org/vuls/id/935424http://www.securityfocus.com/bid/76256https://bugzilla.redhat.com/show_bug.cgi?id=1252096https://www.kb.cert.org/vuls/id/BGAR-A2CNKGhttps://www.kb.cert.org/vuls/id/BLUU-9ZAHZHhttps://www.usenix.org/system/files/conference/woot15/woot15-paper-barresi.pdf
2017-03-03
Published