CVE-2015-1805 is a critical vulnerability in the Linux kernel's pipe_read and pipe_write implementations (fs/pipe.c) affecting versions before 3.16, including Google Android and Linux distributions. This flaw, dubbed an "I/O vector array overrun," stems from improper handling of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls. It carries a high CVSS score of 7.2, indicating a local attack vector with low complexity, allowing unauthenticated local users to cause a denial of service (system crash) or potentially gain privileges. While not listed in CISA's KEV catalog and lacking public Metasploit or ExploitDB modules, the vulnerability garnered significant community discussion and media attention, including reports of Google issuing an emergency patch, suggesting awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.4.3CPE matchmatch criteria | cpe:2.3:o:google:android:4.4.3:*:*:*:*:*:*:* | ||
5.0.1CPE matchmatch criteria | cpe:2.3:o:google:android:5.0.1:*:*:*:*:*:*:* | ||
5.1CPE matchmatch criteria | cpe:2.3:o:google:android:5.1:*:*:*:*:*:*:* | ||
5.1.1CPE matchmatch criteria | cpe:2.3:o:google:android:5.1.1:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.