VYPR
Low severity3.3NVD Advisory· Published Mar 3, 2017· Updated Jun 17, 2026

CVE-2015-2877

CVE-2015-2877

Description

Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection (CAIN) attack. NOTE: the vendor states "Basically if you care about this attack vector, disable deduplication." Share-until-written approaches for memory conservation among mutually untrusting tenants are inherently detectable for information disclosure, and can be classified as potentially misunderstood behaviors rather than vulnerabilities

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • Linux/Kernel2 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=2.6.32,<=4.20.15
    • (no CPE)range: 2.6.32 through 4.x
  • cpe:2.3:o:redhat:enterprise_linux:4.0:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:redhat:enterprise_linux:4.0:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
  • Linux/KSMllm-create
    Range: 2.6.32 through 4.x

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.