PT-2018-4447 · Google · Android Kernel

Ming Lei

·

Published

2018-04-05

·

Updated

2018-05-03

·

CVE-2015-9016

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android kernel
Description The issue is related to a possible use after free due to a race condition in the blk-mq-tag-to-rq function. This could potentially lead to local escalation of privilege.
Recommendations For Android kernel, consider applying a patch to fix the race condition in the blk mq tag to rq function to prevent use after free and potential privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-9016
DSA-4187-1

Affected Products

Android Kernel