ASB-A-158762825

See a problem?
Import Source
https://storage.googleapis.com/android-osv/ASB-A-158762825.json
JSON Data
https://api.osv.dev/v1/vulns/ASB-A-158762825
Aliases
Published
2020-11-01T00:00:00Z
Modified
2026-04-27T15:40:08.012512Z
Summary
[none]
Details

In sbrDecoder_AssignQmfChannels2SbrChannels of sbrdecoder.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.

References

Affected packages

Android
platform/external/aac

Package

Name
platform/external/aac

Affected ranges

Type
ECOSYSTEM
Events
Introduced
11-next:0
Fixed
11-next:2020-11-01

Affected versions

Other
11-next

Ecosystem specific

{
    "vanir_signatures": [
        {
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "142422467020648822547703441017879885274",
                    "228812615875260181430145982279368256482",
                    "176307174465814800197113886399607820925",
                    "69107727275503488440861565140721362218",
                    "255157361079938928212995141838126577939",
                    "160047525827657626340987409945053069165",
                    "187671612728043577690739855739978551429",
                    "330514005037872735567875913459891428879",
                    "220632705698356879282925434135269423181",
                    "140419493687440592138380646523291207659",
                    "33384198807420518707870173108725082983",
                    "270914430008454977006144661128034355017",
                    "24948692722044566004490151449656924695"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/external/aac/+/b5dfe8f92dd94e91f8391a9dc3d1fa7b0415ece2",
            "id": "ASB-A-158762825-1ff635f7",
            "target": {
                "file": "libSBRdec/src/sbrdecoder.cpp"
            }
        },
        {
            "deprecated": false,
            "digest": {
                "length": 4310.0,
                "function_hash": "146558201018791035422978077567348319939"
            },
            "signature_type": "Function",
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/external/aac/+/b5dfe8f92dd94e91f8391a9dc3d1fa7b0415ece2",
            "id": "ASB-A-158762825-5bea0e10",
            "target": {
                "function": "sbrDecoder_InitElement",
                "file": "libSBRdec/src/sbrdecoder.cpp"
            }
        }
    ],
    "fixes": [
        "https://android.googlesource.com/platform/external/aac/+/b5dfe8f92dd94e91f8391a9dc3d1fa7b0415ece2"
    ],
    "spl": "2020-11-01",
    "severity": "Critical",
    "types": [
        "RCE"
    ]
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-158762825.json"
platform/external/aac

Package

Name
platform/external/aac

Affected ranges

Type
ECOSYSTEM
Events
Introduced
8.0:0
Fixed
8.0:2020-11-01

Affected versions

8.*
8.0

Ecosystem specific

{
    "vanir_signatures": [
        {
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "228812615875260181430145982279368256482",
                    "176307174465814800197113886399607820925",
                    "69107727275503488440861565140721362218",
                    "79144432237833794385995381888037130233",
                    "151815700922097067393703470540359404549",
                    "278065597791376900532215424183280781167",
                    "140608842562946831557655018490924436497"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/external/aac/+/50aa5be38870319395ce2ef6f91543e6475e4b97",
            "id": "ASB-A-158762825-00398924",
            "target": {
                "file": "libSBRdec/src/sbrdecoder.cpp"
            }
        },
        {
            "deprecated": false,
            "digest": {
                "length": 3180.0,
                "function_hash": "236513874519966155411576035832073081180"
            },
            "signature_type": "Function",
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/external/aac/+/50aa5be38870319395ce2ef6f91543e6475e4b97",
            "id": "ASB-A-158762825-2f1e9a86",
            "target": {
                "function": "sbrDecoder_InitElement",
                "file": "libSBRdec/src/sbrdecoder.cpp"
            }
        }
    ],
    "fixes": [
        "https://android.googlesource.com/platform/external/aac/+/50aa5be38870319395ce2ef6f91543e6475e4b97"
    ],
    "spl": "2020-11-01",
    "severity": "Critical",
    "types": [
        "RCE"
    ]
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-158762825.json"
platform/external/aac

Package

Name
platform/external/aac

Affected ranges

Type
ECOSYSTEM
Events
Introduced
8.1:0
Fixed
8.1:2020-11-01

Affected versions

8.*
8.1

Ecosystem specific

{
    "vanir_signatures": [
        {
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "228812615875260181430145982279368256482",
                    "176307174465814800197113886399607820925",
                    "69107727275503488440861565140721362218",
                    "79144432237833794385995381888037130233",
                    "151815700922097067393703470540359404549",
                    "278065597791376900532215424183280781167",
                    "140608842562946831557655018490924436497"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/external/aac/+/50aa5be38870319395ce2ef6f91543e6475e4b97",
            "id": "ASB-A-158762825-4ee4b0a6",
            "target": {
                "file": "libSBRdec/src/sbrdecoder.cpp"
            }
        },
        {
            "deprecated": false,
            "digest": {
                "length": 3180.0,
                "function_hash": "236513874519966155411576035832073081180"
            },
            "signature_type": "Function",
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/external/aac/+/50aa5be38870319395ce2ef6f91543e6475e4b97",
            "id": "ASB-A-158762825-933ebaa5",
            "target": {
                "function": "sbrDecoder_InitElement",
                "file": "libSBRdec/src/sbrdecoder.cpp"
            }
        }
    ],
    "fixes": [
        "https://android.googlesource.com/platform/external/aac/+/50aa5be38870319395ce2ef6f91543e6475e4b97"
    ],
    "spl": "2020-11-01",
    "severity": "Critical",
    "types": [
        "RCE"
    ]
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-158762825.json"
platform/external/aac

Package

Name
platform/external/aac

Affected ranges

Type
ECOSYSTEM
Events
Introduced
9:0
Fixed
9:2020-11-01

Affected versions

Other
9

Ecosystem specific

{
    "vanir_signatures": [
        {
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "228812615875260181430145982279368256482",
                    "176307174465814800197113886399607820925",
                    "69107727275503488440861565140721362218",
                    "255157361079938928212995141838126577939",
                    "160047525827657626340987409945053069165",
                    "187671612728043577690739855739978551429",
                    "330514005037872735567875913459891428879",
                    "220632705698356879282925434135269423181",
                    "140419493687440592138380646523291207659",
                    "33384198807420518707870173108725082983",
                    "270914430008454977006144661128034355017",
                    "24948692722044566004490151449656924695"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/external/aac/+/c516539a202b08cda8569a9e58c9dc6097450cbe",
            "id": "ASB-A-158762825-1b2eed57",
            "target": {
                "file": "libSBRdec/src/sbrdecoder.cpp"
            }
        },
        {
            "deprecated": false,
            "digest": {
                "length": 4310.0,
                "function_hash": "146558201018791035422978077567348319939"
            },
            "signature_type": "Function",
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/external/aac/+/c516539a202b08cda8569a9e58c9dc6097450cbe",
            "id": "ASB-A-158762825-ac20c550",
            "target": {
                "function": "sbrDecoder_InitElement",
                "file": "libSBRdec/src/sbrdecoder.cpp"
            }
        }
    ],
    "fixes": [
        "https://android.googlesource.com/platform/external/aac/+/c516539a202b08cda8569a9e58c9dc6097450cbe"
    ],
    "spl": "2020-11-01",
    "severity": "Critical",
    "types": [
        "RCE"
    ]
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-158762825.json"
platform/external/aac

Package

Name
platform/external/aac

Affected ranges

Type
ECOSYSTEM
Events
Introduced
10:0
Fixed
10:2020-11-01

Affected versions

Other
10

Ecosystem specific

{
    "vanir_signatures": [
        {
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "228812615875260181430145982279368256482",
                    "176307174465814800197113886399607820925",
                    "69107727275503488440861565140721362218",
                    "255157361079938928212995141838126577939",
                    "160047525827657626340987409945053069165",
                    "187671612728043577690739855739978551429",
                    "330514005037872735567875913459891428879",
                    "220632705698356879282925434135269423181",
                    "140419493687440592138380646523291207659",
                    "33384198807420518707870173108725082983",
                    "270914430008454977006144661128034355017",
                    "24948692722044566004490151449656924695"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/external/aac/+/c516539a202b08cda8569a9e58c9dc6097450cbe",
            "id": "ASB-A-158762825-039bdc40",
            "target": {
                "file": "libSBRdec/src/sbrdecoder.cpp"
            }
        },
        {
            "deprecated": false,
            "digest": {
                "length": 4310.0,
                "function_hash": "146558201018791035422978077567348319939"
            },
            "signature_type": "Function",
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/external/aac/+/c516539a202b08cda8569a9e58c9dc6097450cbe",
            "id": "ASB-A-158762825-d403db16",
            "target": {
                "function": "sbrDecoder_InitElement",
                "file": "libSBRdec/src/sbrdecoder.cpp"
            }
        }
    ],
    "fixes": [
        "https://android.googlesource.com/platform/external/aac/+/c516539a202b08cda8569a9e58c9dc6097450cbe"
    ],
    "spl": "2020-11-01",
    "severity": "Critical",
    "types": [
        "RCE"
    ]
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-158762825.json"
platform/external/aac

Package

Name
platform/external/aac

Affected ranges

Type
ECOSYSTEM
Events
Introduced
11:0
Fixed
11:2020-11-01

Affected versions

Other
11

Ecosystem specific

{
    "vanir_signatures": [
        {
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "142422467020648822547703441017879885274",
                    "228812615875260181430145982279368256482",
                    "176307174465814800197113886399607820925",
                    "69107727275503488440861565140721362218",
                    "255157361079938928212995141838126577939",
                    "160047525827657626340987409945053069165",
                    "187671612728043577690739855739978551429",
                    "330514005037872735567875913459891428879",
                    "220632705698356879282925434135269423181",
                    "140419493687440592138380646523291207659",
                    "33384198807420518707870173108725082983",
                    "270914430008454977006144661128034355017",
                    "24948692722044566004490151449656924695"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/external/aac/+/bb8f983bf36ee2ad8af6acebf4823a58060004ab",
            "id": "ASB-A-158762825-2b030bdd",
            "target": {
                "file": "libSBRdec/src/sbrdecoder.cpp"
            }
        },
        {
            "deprecated": false,
            "digest": {
                "length": 4310.0,
                "function_hash": "146558201018791035422978077567348319939"
            },
            "signature_type": "Function",
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/external/aac/+/bb8f983bf36ee2ad8af6acebf4823a58060004ab",
            "id": "ASB-A-158762825-90aa67b9",
            "target": {
                "function": "sbrDecoder_InitElement",
                "file": "libSBRdec/src/sbrdecoder.cpp"
            }
        }
    ],
    "fixes": [
        "https://android.googlesource.com/platform/external/aac/+/bb8f983bf36ee2ad8af6acebf4823a58060004ab"
    ],
    "spl": "2020-11-01",
    "severity": "Critical",
    "types": [
        "RCE"
    ]
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-158762825.json"