VYPR
High severity7.8NVD Advisory· Published Jan 6, 2016· Updated Jun 17, 2026

CVE-2015-6640

CVE-2015-6640

Description

The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is accessed in a certain update action, which allows attackers to gain privileges or cause a denial of service (vma list corruption) via a crafted application, aka internal bug 20017123.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Google/Android5 versions
    cpe:2.3:o:google:android:4.4.4:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:o:google:android:4.4.4:*:*:*:*:*:*:*
    • cpe:2.3:o:google:android:5.0:*:*:*:*:*:*:*
    • cpe:2.3:o:google:android:5.1.1:*:*:*:*:*:*:*
    • cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*
    • (no CPE)range: < 5.1.1 LMY49F, < 6.0 before 2016-01-01

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.