CVE Vulnerabilities

CVE-2015-6640

Published: Jan 06, 2016 | Modified: Dec 07, 2016
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is accessed in a certain update action, which allows attackers to gain privileges or cause a denial of service (vma list corruption) via a crafted application, aka internal bug 20017123.

Affected Software

Name Vendor Start Version End Version
Android Google 4.4.4 (including) 4.4.4 (including)
Android Google 5.0 (including) 5.0 (including)
Android Google 5.1.1 (including) 5.1.1 (including)
Android Google 6.0 (including) 6.0 (including)

References