In rndissetresponse of rndis.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "length": 1018.0, "function_hash": "221946459094492974610708965816765957224" }, "id": "ASB-A-162326603-37296d0c", "source": "https://android.googlesource.com/kernel/common/+/38ea1eac7d88072bbffb630e2b3db83ca649b826", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/usb/gadget/function/rndis.c", "function": "rndis_set_response" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "282852417431766263490676553128712597531", "110705312730213592619630503319076438808", "94219566278308689484813984906675955552", "36491830421415711599610514669873140861", "30790627971595482618317624871770110268", "288531739672159843520527013539581497894", "39603869017474101200293526634541239352", "45180091331208902342353969121843865020", "143434519509247879588825429509241155734" ] }, "id": "ASB-A-162326603-50e75451", "source": "https://android.googlesource.com/kernel/common/+/38ea1eac7d88072bbffb630e2b3db83ca649b826", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/usb/gadget/function/rndis.c" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/kernel/common/+/38ea1eac7d88072bbffb630e2b3db83ca649b826" ], "spl": "2022-06-05", "severity": "High", "types": [ "ID" ] }