mm/memory.c in the Linux kernel before 4.1.4 mishandles anonymous pages, which allows local users to gain privileges or cause a denial of service (page tainting) via a crafted application that triggers writing to page zero.
https://source.android.com/security/bulletin/2017-01-01.html
https://security-tracker.debian.org/tracker/CVE-2015-3288