CVE-2015-9004
published 2017-05-02CVE-2015-9004: kernel/events/core.c in the Linux kernel before 3.19 mishandles counter grouping, which allows local users to gain privileges via a crafted application…
PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.84%
53.9th percentile
kernel/events/core.c in the Linux kernel before 3.19 mishandles counter grouping, which allows local users to gain privileges via a crafted application, related to the perf_pmu_register and perf_event_open functions.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.16.7-ckt7-1 (bookworm) | linux 3.16.7-ckt7-1 (bookworm) |
| android | <= 7.1.1 | — | |
| android | — | — | |
| linux | linux_kernel | < 3.2.95 | 3.2.95 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt7-1 | 3.16.7-ckt7-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt7-1 | 3.16.7-ckt7-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt7-1 | 3.16.7-ckt7-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt7-1 | 3.16.7-ckt7-1 |
| linux | linux_kernel | >= 3.10.65 < 3.10.105 | 3.10.105 |
| linux | linux_kernel | >= 3.12 < 3.12.68 | 3.12.68 |
| linux | linux_kernel | >= 3.14.29 < 3.16.35 | 3.16.35 |
| linux | linux_kernel | >= 3.18.3 < 3.18.52 | 3.18.52 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gc4h-46x7-632v: kernel/events/core
ghsa_unreviewed·2022-05-17
CVE-2015-9004 [HIGH] GHSA-gc4h-46x7-632v: kernel/events/core
kernel/events/core.c in the Linux kernel before 3.19 mishandles counter grouping, which allows local users to gain privileges via a crafted application, related to the perf_pmu_register and perf_event_open functions.
OSV
CVE-2015-9004: kernel/events/core
osv·2017-05-02·CVSS 7.8
CVE-2015-9004 [HIGH] CVE-2015-9004: kernel/events/core
kernel/events/core.c in the Linux kernel before 3.19 mishandles counter grouping, which allows local users to gain privileges via a crafted application, related to the perf_pmu_register and perf_event_open functions.
Android
CVE-2015-9004: Android Security Bulletin 2017-05-01
CVE: CVE-2015-9004
Severity: HIGH
References: A-34515362
Upstream kernel
vendor_android·2017-05-01·CVSS 7.8
CVE-2015-9004 [HIGH] CVE-2015-9004: Android Security Bulletin 2017-05-01
CVE: CVE-2015-9004
Severity: HIGH
References: A-34515362
Upstream kernel
Android Security Bulletin 2017-05-01
CVE: CVE-2015-9004
Severity: HIGH
References: A-34515362
Upstream kernel
Red Hat
kernel: Allows creating groups that can't be co-scheduled
vendor_redhat·2015-01-23·CVSS 7.8
CVE-2015-9004 [HIGH] CWE-266 kernel: Allows creating groups that can't be co-scheduled
kernel: Allows creating groups that can't be co-scheduled
kernel/events/core.c in the Linux kernel before 3.19 mishandles counter grouping, which allows local users to gain privileges via a crafted application, related to the perf_pmu_register and perf_event_open functions.
It was found that kernel/events/core.c in the Linux kernel mishandles counter grouping, which allows local users to gain privileges via a crafted application, related to the perf_pmu_register and perf_event_open functions.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 as the code with the flaw is not present in this product.
This issue does not affect the versions of the Linux kernel as shipped with
Red Hat Enterprise Linux 6, 7 and Red Hat Enterprise MRG 2
Debian
CVE-2015-9004: linux - kernel/events/core.c in the Linux kernel before 3.19 mishandles counter grouping...
vendor_debian·2015·CVSS 7.8
CVE-2015-9004 [HIGH] CVE-2015-9004: linux - kernel/events/core.c in the Linux kernel before 3.19 mishandles counter grouping...
kernel/events/core.c in the Linux kernel before 3.19 mishandles counter grouping, which allows local users to gain privileges via a crafted application, related to the perf_pmu_register and perf_event_open functions.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt7-1)
bullseye: resolved (fixed in 3.16.7-ckt7-1)
forky: resolved (fixed in 3.16.7-ckt7-1)
sid: resolved (fixed in 3.16.7-ckt7-1)
trixie: resolved (fixed in 3.16.7-ckt7-1)
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c3c87e770458aa004bd7ed3f29945ff436fd6511http://www.securityfocus.com/bid/98166https://github.com/torvalds/linux/commit/c3c87e770458aa004bd7ed3f29945ff436fd6511https://source.android.com/security/bulletin/2017-05-01http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c3c87e770458aa004bd7ed3f29945ff436fd6511http://www.securityfocus.com/bid/98166https://github.com/torvalds/linux/commit/c3c87e770458aa004bd7ed3f29945ff436fd6511https://source.android.com/security/bulletin/2017-05-01
2017-05-02
Published