CVE-2015-8955

HIGH

Linux Kernel < 4.1 - Denial of Service via Mishandled HW PMU Events

Title source: llm
STIX 2.1

Description

arch/arm64/kernel/perf_event.c in the Linux kernel before 4.1 on arm64 platforms allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via vectors involving events that are mishandled during a span of multiple HW PMUs.

References (4)

Core 4
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://github.com/torvalds/linux/commit/8fff105e13041e49b82f92eef034f363a6b1c071
Third Party Advisory, VDB Entry, URL Repurposed vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93314

Scores

CVSS v3 7.3
EPSS 0.0022
EPSS Percentile 12.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (2)
google/android 7.0
linux/linux_kernel < 3.16.39
Published Oct 10, 2016
Tracked Since Feb 18, 2026