SB2016080606 - Permissions, privileges, and access controls in Linux kernel arm mm
Published: August 6, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, privileges, and access controls (CVE-ID: CVE-2014-9888)
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to permissions, privileges, and access controls error within the __dma_alloc() and arm_dma_alloc() functions in arch/arm/mm/dma-mapping.c. A local user can execute arbitrary code.
Remediation
Install update from vendor's website.
References
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0ea1ec713f04bdfac343c9702b21cd3a7c711826
- http://source.android.com/security/bulletin/2016-08-01.html
- http://www.securityfocus.com/bid/92219
- https://github.com/torvalds/linux/commit/0ea1ec713f04bdfac343c9702b21cd3a7c711826
- https://source.codeaurora.org/quic/la/kernel/msm/commit/?id=f044936caab337a4384fbfe64a4cbae33c7e22a1