← Back

CVE-2015-6640

nvd nist
Published: Jan 6, 2016Modified: May 6, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is accessed in a certain update action, which allows attackers to gain privileges or cause a denial of service (vma list corruption) via a crafted application, aka internal bug 20017123.

Affected (4)

Products: Google: Android
1 product
Android
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Google
Version 4.4.4
Version 5.0
Version 5.1.1
Version 6.0

Related CWEs

References (6)

Timeline

No history available yet.