CVE-2015-8966: High severity Google Android vulnerability
Published Dec 5, 2016
·Updated
arch/arm/kernel/sysoabi-compat.c in the Linux kernel before 4.4 allow ...
Affected Software
3 affected componentsFixes available
Google Android
Linux Linux Kernel<=4.3.6
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.22-16.12.25-1
Remediation
Event History
Dec 5, 2016
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityAffected Software
Dec 8, 2016
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:16 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:12 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2015-8966.
2
What is the severity of CVE-2015-8966?
The severity of CVE-2015-8966 is critical.
3
How can local users gain privileges through CVE-2015-8966?
Local users can gain privileges through a crafted fcntl64 system call with F_OFD_GETLK, F_OFD_SETLK, or F_OFD_SETLKW command.
4
Which versions of Linux are affected by CVE-2015-8966?
Linux kernel versions before 4.4 are affected by CVE-2015-8966.
5
Where can I find more information about CVE-2015-8966?
You can find more information about CVE-2015-8966 at the following references: [Reference 1](http://source.android.com/security/bulletin/2016-12-01.html), [Reference 2](https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=76cc404bfdc0d419c720de4daaf2584542734f42), [Reference 3](https://github.com/torvalds/linux/commit/76cc404bfdc0d419c720de4daaf2584542734f42).