CVE-2015-8955: Google Android

High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.

arch/arm64/kernel/perf_event.c in the Linux kernel before 4.1 on arm64 platforms allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via vectors involving events that are mishandled during a span of multiple HW PMUs.

Affected products

  • Google Android: version 7.0 only
  • Linux Linux Kernel: before 3.16.39 (fixed in 3.16.39); from 3.18, before 3.18.54 (fixed in 3.18.54); from 3.19, before 4.1 (fixed in 4.1)

Published 2016-10-10. Last modified 2026-06-17.