CVE Vulnerabilities

CVE-2015-6640

Published: Jan 06, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is accessed in a certain update action, which allows attackers to gain privileges or cause a denial of service (vma list corruption) via a crafted application, aka internal bug 20017123.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle4.4.4 (including)4.4.4 (including)
AndroidGoogle5.0 (including)5.0 (including)
AndroidGoogle5.1.1 (including)5.1.1 (including)
AndroidGoogle6.0 (including)6.0 (including)
AndroidUbuntuesm-apps/xenial*
AndroidUbuntutrusty*
AndroidUbuntuvivid*
AndroidUbuntuvivid/stable-phone-overlay*
AndroidUbuntuwily*
AndroidUbuntuxenial*
AndroidUbuntuyakkety*
AndroidUbuntuzesty*
LinuxUbuntuvivid*
Linux-floUbuntutrusty*
Linux-floUbuntuvivid*
Linux-goldfishUbuntutrusty*
Linux-goldfishUbuntuvivid*
Linux-grouperUbuntutrusty*
Linux-linaro-omapUbuntuprecise*
Linux-linaro-sharedUbuntuprecise*
Linux-linaro-vexpressUbuntuprecise*
Linux-lts-quantalUbuntuprecise*
Linux-lts-quantalUbuntuprecise/esm*
Linux-lts-raringUbuntuprecise*
Linux-lts-raringUbuntuprecise/esm*
Linux-lts-saucyUbuntuprecise*
Linux-lts-saucyUbuntuprecise/esm*
Linux-maguroUbuntutrusty*
Linux-makoUbuntutrusty*
Linux-makoUbuntuvivid*
Linux-mantaUbuntutrusty*
Linux-mantaUbuntuvivid*
Linux-qcm-msmUbuntuprecise*

References