CVE-2015-6596
Publication date 6 October 2015
Last updated 24 July 2024
Ubuntu priority
Description
mediaserver in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, aka internal bugs 20731946 and 20719651, a different vulnerability than CVE-2015-7717.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| android | ||
| 14.04 LTS trusty | Not in release | |
Notes
sbeattie
additional fix available in the latest binary drivers for Nexus devices (bug 20719651) 9ef830c6dbd4f6000b94abee3df14b9e27a38294 -> android 5-6 only, adds checks on binder calls first patch addresses mutliple crash issues related to threads in audio flinger
jdstrand
Ubuntu does not use audio flinger
References
Other references
- https://groups.google.com/forum/#!topic/android-security-updates/iv1BF0f0XY4
- https://android.googlesource.com/platform/frameworks/av/+/b97ee930e4f7ed1587b869c92b4aa1dc90b641cc%5E!/#F0
- https://android.googlesource.com/platform/frameworks/av/+/9ef830c6dbd4f6000b94abee3df14b9e27a38294%5E!/#F0
- https://www.cve.org/CVERecord?id=CVE-2015-6596