CVE Radar

CVE Radar Logo
CVERadar

Edition used by more than 30,000 companies in more than 150 countries.
Sign Up For Free

CVE-2024-0564

Medium Severity|Linux
38
SVRS
6.5
CVSSv3
0.00023
EPSS
TAGSNo tags available
VECTOR STRING
CVSS:3.1AV:AAC:LPR:NUI:NS:UC:HI:NA:N
PUBLICATION DATE2024-01-30
LAST MODIFIED2025-11-21

Deep CVE Analysis in Progress

The system is currently conducting an in-depth analysis of the selected CVE. This includes advanced correlation, vulnerability classification, and cross-referencing with real-time threat intelligence sources. Once the analysis is complete, the page will automatically update with enriched vulnerability data and actionable insights.

Security Intelligence Brief

What is this vulnerability and why does it matter?
This vulnerability, identified as CVE-2024-0564, is a side-channel flaw found in the Linux kernel's memory deduplication mechanism, specifically within the Kernel Samepage Merging (KSM) feature. The 'max page sharing' aspect of KSM, introduced in Linux kernel version 4.4.0-96.119, can be exploited by an attacker. It matters because if an attacker and a victim share the same host, this flaw can allow the attacker to leak sensitive information from the victim's memory pages.
What are the CVSS score, severity level, and disclosure details?
The CVSS score for this vulnerability is 6.5, which typically corresponds to a Medium severity level. The vulnerability was publicly disclosed and published on 2024-01-30 15:01:08. The CVE record was last modified on 2025-11-21 06:24:25.
Which products, vendors, systems, and versions are affected?
This vulnerability affects systems running the Linux kernel. Specifically, any Linux kernel version from 4.4.0-96.119 onwards that includes the KSM 'max page sharing' feature and has not yet been patched is considered vulnerable.
What is the technical root cause and attack vector?
The technical root cause lies within a design flaw in the Kernel Samepage Merging (KSM) memory deduplication mechanism of the Linux kernel. When the default setting of KSM's "max page sharing=256" is active, an attacker can leverage a timing side channel. The attack vector involves an attacker co-resident on the same host as the victim, exploiting the timing differences observed during memory unmapping operations, particularly when additional physical pages are created beyond KSM's maximum shared page limit.
How can this vulnerability be exploited?
Exploitation of CVE-2024-0564 requires the attacker and the victim to share the same host. The attacker can exploit this by precisely timing the unmap operation of memory pages. If the attacker's unmap operation merges with a victim's page, and this action leads to the creation of additional physical pages beyond the KSM's "max page share" threshold (e.g., 256), the timing difference of this operation can be observed. This observed timing variation constitutes a side channel that allows the attacker to infer and subsequently leak content from the victim's memory pages.
How can vulnerable systems be detected?
Vulnerable systems can be detected by identifying the version of the Linux kernel in use. Systems running Linux kernel version 4.4.0-96.119 or any subsequent version that incorporates the KSM 'max page sharing' feature and has not received a patch for CVE-2024-0564 are vulnerable. Administrators should check their kernel versions and KSM configuration settings.
What public intelligence references and advisories exist?
The primary public intelligence reference for this vulnerability is its CVE identifier, CVE-2024-0564. The vulnerability was published on 2024-01-30 15:01:08, providing initial public awareness and details.
What is the risk assessment and urgency level?
The risk associated with CVE-2024-0564 is Medium, as indicated by its CVSS score of 6.5. This vulnerability allows for information leakage through a side-channel attack, which requires specific conditions, primarily co-tenancy on the same host as the victim. While not enabling direct arbitrary code execution, the potential for sensitive data exposure makes it a significant concern, especially in multi-tenant environments such as cloud computing platforms. The urgency level is moderate to high, depending on the environment's security posture and the sensitivity of data processed on shared hosts. Organizations operating virtualized or cloud environments where KSM is enabled should prioritize assessment and patching.

No IOCs found for this CVE

No exploits found for this CVE

SOCRadar Logo

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence

Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.

CREATE FREE ACCOUNT
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs
CVE-2024-0564 | Linux Kernel up to 5.15.0-58 KSM memory corruption (EUVD-2024-16357 / Nessus ID 227872)
vuldb.com2025-09-14
CVE-2024-0564 | Linux Kernel up to 5.15.0-58 KSM memory corruption (EUVD-2024-16357 / Nessus ID 227872) | A vulnerability labeled as critical has been found in Linux Kernel up to 5.15.0-58. Impacted is an unknown function of the component KSM. Executing manipulation can lead to memory corruption. The identification of this vulnerability is CVE-2024-0564. The attack needs to be done
vuldb.comrssforumnews

No tweets found for this CVE

Configuration 1
TypeVendorProduct
OSLinuxlinux_kernel
Configuration 2
TypeVendorProduct
OSRedhatenterprise_linux
ReferenceLink
RHBZ#2258514https://bugzilla.redhat.com/show_bug.cgi?id=2258514
[email protected]https://access.redhat.com/security/cve/CVE-2024-0564
[email protected]https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1680513
[email protected]https://bugzilla.redhat.com/show_bug.cgi?id=2258514
[email protected]https://link.springer.com/conference/wisa
[email protected]https://wisa.or.kr/accepted
RHBZ#2258514https://bugzilla.redhat.com/show_bug.cgi?id=2258514
CWE IDCWE NameDescription
CWE-99Improper Control of Resource Identifiers ('Resource Injection')The software receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control.
CWE-203Observable DiscrepancyThe product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.