CVE Vulnerabilities

CVE-2015-8890

Published: Jul 11, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

platform/msm_shared/partition_parser.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices does not validate certain GUID Partition Table (GPT) data, which allows attackers to bypass intended access restrictions via a crafted MultiMediaCard (MMC), aka Android internal bug 28822878 and Qualcomm internal bug CR823461.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle*6.0.1 (including)
Linux-floUbuntutrusty*
Linux-goldfishUbuntutrusty*
Linux-grouperUbuntutrusty*
Linux-linaro-omapUbuntuprecise*
Linux-linaro-sharedUbuntuprecise*
Linux-linaro-vexpressUbuntuprecise*
Linux-lts-quantalUbuntuprecise*
Linux-lts-raringUbuntuprecise*
Linux-lts-saucyUbuntuprecise*
Linux-maguroUbuntutrusty*
Linux-makoUbuntutrusty*
Linux-mantaUbuntutrusty*
Linux-qcm-msmUbuntuprecise*

References