The sockets subsystem in Android 6.x before 2016-07-01 allows attackers to bypass intended system-call restrictions via a crafted application that makes an ioctl call, aka internal bug 28171804.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.