High severity7.8NVD Advisory· Published Jan 6, 2016· Updated Jun 17, 2026
CVE-2015-6640
CVE-2015-6640
Description
The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is accessed in a certain update action, which allows attackers to gain privileges or cause a denial of service (vma list corruption) via a crafted application, aka internal bug 20017123.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:o:google:android:4.4.4:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:o:google:android:4.4.4:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:5.0:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:5.1.1:*:*:*:*:*:*:*
- cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*
- (no CPE)range: < 5.1.1 LMY49F, < 6.0 before 2016-01-01
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.