Race condition in the ion_ioctl function in drivers/staging/android/ion/ion.c in the Linux kernel before 4.6 allows local users to gain privileges or cause a denial of service (use-after-free) by calling ION_IOC_FREE on two CPUs at the same time.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Linux_kernel | Linux | 3.14 (including) | 3.16.40 (excluding) |
Linux_kernel | Linux | 3.17 (including) | 3.18.51 (excluding) |
Linux_kernel | Linux | 3.19 (including) | 4.1.41 (excluding) |
Linux_kernel | Linux | 4.2 (including) | 4.4.65 (excluding) |
Linux_kernel | Linux | 4.5 (including) | 4.6 (excluding) |