Vulnerability Name: | CVE-2015-8966 (CCN-120133) | ||||||||||||||||||||||||
Assigned: | 2016-10-03 | ||||||||||||||||||||||||
Published: | 2016-10-03 | ||||||||||||||||||||||||
Updated: | 2016-12-10 | ||||||||||||||||||||||||
Summary: | arch/arm/kernel/sys_oabi-compat.c in the Linux kernel before 4.4 allows local users to gain privileges via a crafted (1) F_OFD_GETLK, (2) F_OFD_SETLK, or (3) F_OFD_SETLKW command in an fcntl64 system call. | ||||||||||||||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-8966 Source: CONFIRM Type: Third Party Advisory http://source.android.com/security/bulletin/2016-12-01.html Source: BID Type: UNKNOWN 94673 Source: CCN Type: BID-94673 Linux Kernel CVE-2015-8966 Local Privilege Escalation Vulnerability Source: XF Type: UNKNOWN linux-kernel-cve20158966-priv-esc(120133) Source: CCN Type: Linux Kernel GIT Repository [PATCH] arm: fix handling of F_OFD_... in oabi_fcntl64() Source: CONFIRM Type: Issue Tracking, Patch, Vendor Advisory https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=76cc404bfdc0d419c720de4daaf2584542734f42 Source: CONFIRM Type: Issue Tracking, Patch, Third Party Advisory https://github.com/torvalds/linux/commit/76cc404bfdc0d419c720de4daaf2584542734f42 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |