CVE-2015-8967: Critical severity Google Android vulnerability
arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to bypass the "strict page permissions" protection mechanism and modify the system-call table, and consequently gain privileges, by leveraging write access.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2015-8967?
CVE-2015-8967 is a vulnerability in the Linux kernel that allows local users to bypass page permissions and modify the system-call table to gain privileges.
How severe is CVE-2015-8967?
CVE-2015-8967 has a severity rating of high, with a severity value of 7.
Which software versions are affected by CVE-2015-8967?
The Linux kernel versions before 4.0 are affected by CVE-2015-8967.
How can I fix CVE-2015-8967?
To fix CVE-2015-8967, update your Linux kernel to version 4.0 or later.
Where can I find more information about CVE-2015-8967?
You can find more information about CVE-2015-8967 in the references provided: [Link 1](http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c623b33b4e9599c6ac5076f7db7369eb9869aa04), [Link 2](http://source.android.com/security/bulletin/2016-12-01.html), [Link 3](https://github.com/torvalds/linux/commit/c623b33b4e9599c6ac5076f7db7369eb9869aa04).