peter bassill · operator
$ cve CVE-2015-0565 JSON

CVE-2015-0565 EXPLOIT

10.0
CRITICAL · CVSS 3.1 · EPSS 13.6% (pctl 96)

Patch early

A public exploit exists.

Description

NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS13.57% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2020-02-25
Last modified2026-06-17

Affected (1)

VendorProduct
googlenative client

Public exploits

SourceTitleDate
exploit-dbLinux Kernel (x86-64) - Rowhammer Privilege Escalation2015-03-09
exploit-dbRowhammer - NaCl Sandbox Escape2015-03-09

References

→ the Explorer  ·  watch your stack  ·  NVD