CVE-2015-8961: Use After Free
Published Nov 7, 2016
·Updated
The ext4journalstop function in fs/ext4/ext4jbd2.c in the Linux kernel before 4.3.3 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging improper access to a certain error field.
Affected Software
8 affected components
Google Android
Linux Linux Kernel>=3.10.85<3.12
Linux Linux Kernel>=3.12.46<3.12.52
Linux Linux Kernel>=3.14.49<3.14.59
Linux Linux Kernel>=3.18.20<3.18.54
Linux Linux Kernel>=4.1.4<4.1.15
Linux Linux Kernel>=4.2<4.2.8
Linux Linux Kernel>=4.3<4.3.3
Remediation
Event History
Nov 7, 2016
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityAffected Software
Nov 16, 2016
CVE Published
via MITRE·04:49 AM
Data Sourced
via MITRE·04:49 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8961?
CVE-2015-8961 has a medium severity rating due to its potential for local privilege escalation and denial of service.
2
How do I fix CVE-2015-8961?
To fix CVE-2015-8961, you should update your Linux kernel to version 4.3.3 or later.
3
Which Linux kernel versions are affected by CVE-2015-8961?
CVE-2015-8961 affects Linux kernel versions prior to 4.3.3.
4
Can CVE-2015-8961 affect Android devices?
Yes, CVE-2015-8961 can potentially affect certain versions of the Android operating system.
5
What type of vulnerability is CVE-2015-8961?
CVE-2015-8961 is classified as a use-after-free vulnerability leading to potential privilege escalation.