CVE Vulnerabilities

CVE-2015-6642

Published: Jan 06, 2016 | Modified: Dec 07, 2016
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The kernel in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24157888.

Affected Software

Name Vendor Start Version End Version
Android Google 5.1.0 5.1.0
Android Google 6.0 6.0
Android Google 6.0.1 6.0.1
Linux Ubuntu vivid *
Linux-flo Ubuntu trusty *
Linux-flo Ubuntu vivid *
Linux-flo Ubuntu vivid/stable-phone-overlay *
Linux-goldfish Ubuntu trusty *
Linux-goldfish Ubuntu vivid *
Linux-grouper Ubuntu trusty *
Linux-linaro-omap Ubuntu precise *
Linux-linaro-shared Ubuntu precise *
Linux-linaro-vexpress Ubuntu precise *
Linux-lts-quantal Ubuntu precise *
Linux-lts-raring Ubuntu precise *
Linux-lts-saucy Ubuntu precise *
Linux-maguro Ubuntu trusty *
Linux-mako Ubuntu trusty *
Linux-mako Ubuntu vivid *
Linux-mako Ubuntu vivid/stable-phone-overlay *
Linux-manta Ubuntu trusty *
Linux-manta Ubuntu vivid *
Linux-qcm-msm Ubuntu precise *

References