CVE-2015-9016 describes a use-after-free vulnerability in the Android kernel's block multi-queue (blk-mq) subsystem, specifically within the blk_mq_tag_to_rq function in blk-mq.c. This flaw, caused by a race condition when a request is freed prematurely, could allow a local attacker to achieve escalation of privilege. With a CVSS v3.0 score of 7.0 (HIGH), exploitation requires local access and high attack complexity, but could lead to complete compromise of confidentiality, integrity, and availability. There is no known public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.