CVE-2015-8962: Double Free
Published Nov 7, 2016
·Updated
Double free vulnerability in the sgcommonwrite function in drivers/s ...
Affected Software
8 affected componentsFixes available
Google Android
Linux Linux Kernel<3.2.85
Linux Linux Kernel>=3.3<3.10.107
Linux Linux Kernel>=3.12<3.12.70
Linux Linux Kernel>=3.13<3.16.40
Linux Linux Kernel>=3.17<3.18.54
Linux Linux Kernel>=3.19<4.4
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-1
Remediation
Event History
Nov 7, 2016
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityAffected Software
Nov 16, 2016
CVE Published
via MITRE·04:49 AM
Data Sourced
via MITRE·04:49 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:16 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:12 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2015-8962.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Double free vulnerability in the sg_common_write function in drivers/scsi/sg.c in the Linux kernel'.
3
What is the description of this vulnerability?
The description of this vulnerability is that it allows local users to gain privileges or cause a denial of service by detaching a device during an SG_IO ioctl call.
4
What is the severity of this vulnerability?
The severity of this vulnerability is critical.
5
How can I fix this vulnerability?
To fix this vulnerability, you should update your Linux kernel to version 4.4 or later.