CVE-2024-0564
Kernel: max page sharing of kernel samepage merging (ksm) may cause memory deduplication
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and the victim share the same host and the default setting of KSM is "max page sharing=256", it is possible for the attacker to time the unmap to merge with the victim's page. The unmapping time depends on whether it merges with the victim's page and additional physical pages are created beyond the KSM's "max page share". Through these operations, the attacker can leak the victim's page.
Se encontró un fallo en el mecanismo de deduplicación de memoria del kernel de Linux. El uso compartido máximo de páginas de Kernel Samepage Merging (KSM), agregado en la versión 4.4.0-96.119 del kernel de Linux, puede crear un canal lateral. Cuando el atacante y la víctima comparten el mismo host y la configuración predeterminada de KSM es "max page sharing=256", es posible que el atacante programe la desasignación para fusionarse con la página de la víctima. El tiempo de desasignación depende de si se fusiona con la página de la víctima y si se crean páginas físicas adicionales más allá del "max page share" de KSM. Mediante estas operaciones, el atacante puede filtrar la página de la víctima.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2024-01-15 CVE Reserved
- 2024-01-30 CVE Published
- 2024-02-09 EPSS Updated
- 2024-10-16 CVE Updated
- 2024-10-16 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-99: Improper Control of Resource Identifiers ('Resource Injection')
- CWE-203: Observable Discrepancy
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://access.redhat.com/security/cve/CVE-2024-0564 | Third Party Advisory | |
https://bugzilla.redhat.com/show_bug.cgi?id=2258514 | Issue Tracking | |
https://link.springer.com/conference/wisa | Not Applicable | |
https://wisa.or.kr/accepted | Not Applicable |
URL | Date | SRC |
---|---|---|
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1680513 | 2024-10-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 4.4.0-96.119 <= 5.15.0-58 Search vendor "Linux" for product "Linux Kernel" and version " >= 4.4.0-96.119 <= 5.15.0-58" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 8.0 Search vendor "Redhat" for product "Enterprise Linux" and version "8.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 9.0 Search vendor "Redhat" for product "Enterprise Linux" and version "9.0" | - |
Affected
|