CVE-2015-9004: Google Android

High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.

kernel/events/core.c in the Linux kernel before 3.19 mishandles counter grouping, which allows local users to gain privileges via a crafted application, related to the perf_pmu_register and perf_event_open functions.

Affected products

  • Google Android: up to and including 7.1.1
  • Linux Linux Kernel: before 3.2.95 (fixed in 3.2.95); from 3.10.65, before 3.10.105 (fixed in 3.10.105); from 3.12, before 3.12.68 (fixed in 3.12.68); from 3.14.29, before 3.16.35 (fixed in 3.16.35); from 3.18.3, before 3.18.52 (fixed in 3.18.52)

Published 2017-05-02. Last modified 2026-06-17.