CVE-2015-8955: Google Android
High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.
arch/arm64/kernel/perf_event.c in the Linux kernel before 4.1 on arm64 platforms allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via vectors involving events that are mishandled during a span of multiple HW PMUs.
Affected products
- Google Android: version 7.0 only
- Linux Linux Kernel: before 3.16.39 (fixed in 3.16.39); from 3.18, before 3.18.54 (fixed in 3.18.54); from 3.19, before 4.1 (fixed in 4.1)
Published 2016-10-10. Last modified 2026-06-17.