In cet4tdatacback of cet4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"length": 5507.0,
"function_hash": "104878374239606386092160028817565736155"
},
"id": "ASB-A-221862119-61ece92b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/nfc/+/2fcf7d677bcebae5a00db43938460bcce267149e",
"target": {
"function": "ce_t4t_data_cback",
"file": "src/nfc/tags/ce_t4t.cc"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"288755587739503399973484087706792439868",
"235957353039854732531163373805571340181",
"178676705441890409717555889950227732401",
"126937206315459210288597319086747904932"
]
},
"id": "ASB-A-221862119-736012b3",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/nfc/+/2fcf7d677bcebae5a00db43938460bcce267149e",
"target": {
"file": "src/nfc/tags/ce_t4t.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/nfc/+/2fcf7d677bcebae5a00db43938460bcce267149e"
],
"types": [
"RCE"
],
"spl": "2022-06-01",
"severity": "Critical"
}
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"288755587739503399973484087706792439868",
"235957353039854732531163373805571340181",
"178676705441890409717555889950227732401",
"126937206315459210288597319086747904932"
]
},
"id": "ASB-A-221862119-343dd870",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/nfc/+/2fcf7d677bcebae5a00db43938460bcce267149e",
"target": {
"file": "src/nfc/tags/ce_t4t.cc"
}
},
{
"digest": {
"length": 5507.0,
"function_hash": "104878374239606386092160028817565736155"
},
"id": "ASB-A-221862119-aa044d21",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/nfc/+/2fcf7d677bcebae5a00db43938460bcce267149e",
"target": {
"function": "ce_t4t_data_cback",
"file": "src/nfc/tags/ce_t4t.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/nfc/+/2fcf7d677bcebae5a00db43938460bcce267149e"
],
"types": [
"RCE"
],
"spl": "2022-06-01",
"severity": "Critical"
}
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"288755587739503399973484087706792439868",
"235957353039854732531163373805571340181",
"178676705441890409717555889950227732401",
"126937206315459210288597319086747904932"
]
},
"id": "ASB-A-221862119-5b367f01",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/nfc/+/2fcf7d677bcebae5a00db43938460bcce267149e",
"target": {
"file": "src/nfc/tags/ce_t4t.cc"
}
},
{
"digest": {
"length": 5507.0,
"function_hash": "104878374239606386092160028817565736155"
},
"id": "ASB-A-221862119-91204f54",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/nfc/+/2fcf7d677bcebae5a00db43938460bcce267149e",
"target": {
"function": "ce_t4t_data_cback",
"file": "src/nfc/tags/ce_t4t.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/nfc/+/2fcf7d677bcebae5a00db43938460bcce267149e"
],
"types": [
"RCE"
],
"spl": "2022-06-01",
"severity": "Critical"
}
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"288755587739503399973484087706792439868",
"235957353039854732531163373805571340181",
"178676705441890409717555889950227732401",
"126937206315459210288597319086747904932"
]
},
"id": "ASB-A-221862119-5008a5a6",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/nfc/+/2fcf7d677bcebae5a00db43938460bcce267149e",
"target": {
"file": "src/nfc/tags/ce_t4t.cc"
}
},
{
"digest": {
"length": 5507.0,
"function_hash": "104878374239606386092160028817565736155"
},
"id": "ASB-A-221862119-bb145cbc",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/nfc/+/2fcf7d677bcebae5a00db43938460bcce267149e",
"target": {
"function": "ce_t4t_data_cback",
"file": "src/nfc/tags/ce_t4t.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/nfc/+/2fcf7d677bcebae5a00db43938460bcce267149e"
],
"types": [
"RCE"
],
"spl": "2022-06-01",
"severity": "Critical"
}
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"288755587739503399973484087706792439868",
"235957353039854732531163373805571340181",
"178676705441890409717555889950227732401",
"126937206315459210288597319086747904932"
]
},
"id": "ASB-A-221862119-4be8c439",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/nfc/+/2fcf7d677bcebae5a00db43938460bcce267149e",
"target": {
"file": "src/nfc/tags/ce_t4t.cc"
}
},
{
"digest": {
"length": 5507.0,
"function_hash": "104878374239606386092160028817565736155"
},
"id": "ASB-A-221862119-ace169cf",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/nfc/+/2fcf7d677bcebae5a00db43938460bcce267149e",
"target": {
"function": "ce_t4t_data_cback",
"file": "src/nfc/tags/ce_t4t.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/nfc/+/2fcf7d677bcebae5a00db43938460bcce267149e"
],
"types": [
"RCE"
],
"spl": "2022-06-01",
"severity": "Critical"
}