Android kernel/sys. c Privilege Escalation Vulnerability (CVE-2015-6640)
Android kernel/sys. c Privilege Escalation Vulnerability (CVE-2015-6640)
Release date:
Updated on:
Affected Systems:
Android <5.1.1 LMY49F
Android 6.0 (<)
Description:
CVE (CAN) ID: CVE-2015-6640
Android is a mobile phone operating system based on the Linux open kernel.
In versions earlier than Android 5.1.1 LMY49F and earlier than 6.0, the prctl_set_vma_anon_name function in kernel/sys. c does not ensure that only one vma is accessed in an update operation, and there is a security vulnerability in implementation. Remote attackers can exploit the constructed applications to gain elevated permissions or cause DoS attacks.
<* Source: Yabin Cui
*>
Suggestion:
Vendor patch:
Android
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://source.android.com/security/bulletin/2016-01-01.html
This article permanently updates the link address: