CVE-2015-9016
published 2018-04-05CVE-2015-9016: In blk_mq_tag_to_rq in blk-mq.c in the upstream kernel, there is a possible use after free due to a race condition when a request has been previously freed by…
PriorityP431high7CVSS 3.0
AVLACHPRLUINSUCHIHAH
EPSS
0.15%
4.3th percentile
In blk_mq_tag_to_rq in blk-mq.c in the upstream kernel, there is a possible use after free due to a race condition when a request has been previously freed by blk_mq_complete_request. This could lead to local escalation of privilege. Product: Android. Versions: Android kernel. Android ID: A-63083046.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.2.3-1 (bookworm) | linux 4.2.3-1 (bookworm) |
| android | — | — | |
| google_inc | android | — | — |
| linux | linux_kernel | >= 0 < 4.2.3-1 | 4.2.3-1 |
| linux | linux_kernel | >= 0 < 4.2.3-1 | 4.2.3-1 |
| linux | linux_kernel | >= 0 < 4.2.3-1 | 4.2.3-1 |
| linux | linux_kernel | >= 0 < 4.2.3-1 | 4.2.3-1 |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2015-9016: Multi-queue block IO
vendor_android·2018-02-01·CVSS 7.0
CVE-2015-9016 [HIGH] CVE-2015-9016: Multi-queue block IO
Android Security Bulletin 2018-02-01
CVE: CVE-2015-9016
Severity: HIGH
Type: EoP
Component: Multi-queue block IO
References: A-63083046
Upstream kernel
Red Hat
kernel: Race condition in block/blk-mq.c:blk_mq_tag_to_rq() can lead to kernel oops
vendor_redhat·2015-08-09·CVSS 7.0
CVE-2015-9016 [HIGH] CWE-362 kernel: Race condition in block/blk-mq.c:blk_mq_tag_to_rq() can lead to kernel oops
kernel: Race condition in block/blk-mq.c:blk_mq_tag_to_rq() can lead to kernel oops
In blk_mq_tag_to_rq in blk-mq.c in the upstream kernel, there is a possible use after free due to a race condition when a request has been previously freed by blk_mq_complete_request. This could lead to local escalation of privilege. Product: Android. Versions: Android kernel. Android ID: A-63083046.
A race condition was found in the block multi queue subsystem of the Linux kernel. This may lead to a kernel panic or have another unknown side affect.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enter
Debian
CVE-2015-9016: linux - In blk_mq_tag_to_rq in blk-mq.c in the upstream kernel, there is a possible use ...
vendor_debian·2015·CVSS 7.0
CVE-2015-9016 [HIGH] CVE-2015-9016: linux - In blk_mq_tag_to_rq in blk-mq.c in the upstream kernel, there is a possible use ...
In blk_mq_tag_to_rq in blk-mq.c in the upstream kernel, there is a possible use after free due to a race condition when a request has been previously freed by blk_mq_complete_request. This could lead to local escalation of privilege. Product: Android. Versions: Android kernel. Android ID: A-63083046.
Scope: local
bookworm: resolved (fixed in 4.2.3-1)
bullseye: resolved (fixed in 4.2.3-1)
forky: resolved (fixed in 4.2.3-1)
sid: resolved (fixed in 4.2.3-1)
trixie: resolved (fixed in 4.2.3-1)
GHSA
GHSA-6q4m-7h3g-6qjr: In blk_mq_tag_to_rq in blk-mq
ghsa_unreviewed·2022-05-14
CVE-2015-9016 [HIGH] GHSA-6q4m-7h3g-6qjr: In blk_mq_tag_to_rq in blk-mq
In blk_mq_tag_to_rq in blk-mq.c in the upstream kernel, there is a possible use after free due to a race condition when a request has been previously freed by blk_mq_complete_request. This could lead to local escalation of privilege. Product: Android. Versions: Android kernel. Android ID: A-63083046.
OSV
CVE-2015-9016: In blk_mq_tag_to_rq in blk-mq
osv·2018-04-05·CVSS 7.0
CVE-2015-9016 [HIGH] CVE-2015-9016: In blk_mq_tag_to_rq in blk-mq
In blk_mq_tag_to_rq in blk-mq.c in the upstream kernel, there is a possible use after free due to a race condition when a request has been previously freed by blk_mq_complete_request. This could lead to local escalation of privilege. Product: Android. Versions: Android kernel. Android ID: A-63083046.
No detection rules found.
No public exploits indexed.
https://github.com/torvalds/linux/commit/0048b4837affd153897ed1222283492070027aa9https://source.android.com/security/bulletin/2018-02-01https://www.debian.org/security/2018/dsa-4187https://github.com/torvalds/linux/commit/0048b4837affd153897ed1222283492070027aa9https://source.android.com/security/bulletin/2018-02-01https://www.debian.org/security/2018/dsa-4187
2018-04-05
Published