kernel/events/core.c in the performance subsystem in the Linux kernel before 4.0 mismanages locks during certain migrations, which allows local users to gain privileges via a crafted application, aka Android internal bug 30955111.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f63a8daa5812afef4f06c962351687e1ff9ccb2b | patch vendor advisory |
https://github.com/torvalds/linux/commit/f63a8daa5812afef4f06c962351687e1ff9ccb2b | patch vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1403842 | issue tracking third party advisory |
http://www.securityfocus.com/bid/94679 | vdb entry third party advisory |
http://www.debian.org/security/2017/dsa-3791 | third party advisory vendor advisory |
http://source.android.com/security/bulletin/2016-12-01.html | third party advisory |