CVE-2015-9165: Double Free
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 617, SD 650/52, SD 808, and SD 810, incorrect error handling could lead to a double free in QTEE file service API.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-9165?
CVE-2015-9165 is a vulnerability in Android devices before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear, which leads to a double free error due to incorrect error handling.
How severe is CVE-2015-9165?
CVE-2015-9165 has a severity rating of 9.8 (Critical).
Which devices are affected by CVE-2015-9165?
Android devices with Qualcomm Snapdragon Mobile and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 617, SD 650/52, SD 808, and SD 810 are affected by CVE-2015-9165.
How can I fix CVE-2015-9165?
To fix CVE-2015-9165, upgrade your Android device to a security patch level after 2018-04-05 or install the appropriate security patch for your Qualcomm Snapdragon Mobile or Snapdragon Wear device.
Where can I find more information about CVE-2015-9165?
You can find more information about CVE-2015-9165 on the following pages: [SecurityFocus](http://www.securityfocus.com/bid/103671), [Android Security Bulletin - 2018-04-01](https://source.android.com/security/bulletin/2018-04-01), [Android Security Bulletin - 2018-04-01 (Asterisk)](https://source.android.com/docs/security/bulletin/2018-04-01/#asterisk).