CVE-2015-6640: Critical severity android vulnerability
The prctlsetvmaanonname function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is accessed in a certain update action, which allows attackers to gain privileges or cause a denial of service (vma list corruption) via a crafted application, aka internal bug 20017123.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6640?
CVE-2015-6640 has a high severity rating due to its potential to allow privilege escalation and denial of service.
How do I fix CVE-2015-6640?
To resolve CVE-2015-6640, you should update your Android device to version 6.0 or later.
What versions of Android are affected by CVE-2015-6640?
CVE-2015-6640 affects Android versions 4.4.4, 5.0, 5.1.1, and all versions before 6.0.
Can CVE-2015-6640 lead to data loss?
Yes, CVE-2015-6640 can potentially lead to data loss due to vma list corruption.
Who is impacted by CVE-2015-6640?
Users of older Android versions prior to 6.0 are at risk of being impacted by CVE-2015-6640.