CVE Vulnerabilities

CVE-2015-6642

Published: Jan 06, 2016 | Modified: Apr 12, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The kernel in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24157888.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle5.1.0 (including)5.1.0 (including)
AndroidGoogle6.0 (including)6.0 (including)
AndroidGoogle6.0.1 (including)6.0.1 (including)
LinuxUbuntuvivid*
Linux-floUbuntutrusty*
Linux-floUbuntuvivid*
Linux-floUbuntuvivid/stable-phone-overlay*
Linux-goldfishUbuntutrusty*
Linux-goldfishUbuntuvivid*
Linux-grouperUbuntutrusty*
Linux-linaro-omapUbuntuprecise*
Linux-linaro-sharedUbuntuprecise*
Linux-linaro-vexpressUbuntuprecise*
Linux-lts-quantalUbuntuprecise*
Linux-lts-raringUbuntuprecise*
Linux-lts-saucyUbuntuprecise*
Linux-maguroUbuntutrusty*
Linux-makoUbuntutrusty*
Linux-makoUbuntuvivid*
Linux-makoUbuntuvivid/stable-phone-overlay*
Linux-mantaUbuntutrusty*
Linux-mantaUbuntuvivid*
Linux-qcm-msmUbuntuprecise*

References