CVE-2016-9120: Use After Free
Race condition in the ionioctl function in drivers/staging/android/ion/ion.c in the Linux kernel before 4.6 allows local users to gain privileges or cause a denial of service (use-after-free) by calling IONIOCFREE on two CPUs at the same time.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9120?
CVE-2016-9120 has been classified as a high severity vulnerability due to its potential for privilege escalation and causing a denial of service.
How do I fix CVE-2016-9120?
To fix CVE-2016-9120, upgrade to a Linux kernel version 4.6 or later where the vulnerability has been patched.
What does CVE-2016-9120 affect?
CVE-2016-9120 affects the Linux kernel versions prior to 4.6 and also impacts certain versions of Android.
What is the risk of not addressing CVE-2016-9120?
Failure to address CVE-2016-9120 may allow attackers to exploit the race condition, leading to privilege escalation or system crashes.
How can I determine if my system is vulnerable to CVE-2016-9120?
Check if your Linux kernel version is below 4.6 or if your Android version is affected by the specific versions listed for CVE-2016-9120.