Fix event->ctx locking in kernel-perf CVE-2016-6786 CVE-2016-6787

Tracked by Jolla

asked 2017-07-13 16:05:44 +0300

this post is marked as community wiki

This post is a wiki. Anyone with karma >75 is welcome to improve it.

updated 2017-07-13 16:07:50 +0300

lpr gravatar image

kernel/events/core.c in the performance subsystem in the Linux kernel before 4.0 mismanages locks during certain migrations, which allows local users to gain privileges via a crafted application, aka Android internal bug 30955111. CVSS v3 Base Score: 7.0 High Access Vector: Locally exploitable

upstream-Patch and kernel-3.2-backport available, so fix for kernel-3.4-sbj will need the appropriate of each...

file affected: /kernel-adaptation-sbj-3.4.108.20161101.1/kernel/events/core.c

edit retag flag offensive close delete