In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"severity": "High",
"spl": "2022-11-01",
"vanir_signatures": [
{
"signature_type": "Function",
"digest": {
"length": 2823.0,
"function_hash": "198204764386842363082619558940037718463"
},
"id": "ASB-A-237540408-27543f3e",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/frameworks/base/+/18f2ec86d680bff26ce9248061878894ad16e05f",
"target": {
"file": "services/core/java/com/android/server/notification/NotificationManagerService.java",
"function": "buzzBeepBlinkLocked"
}
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"298405840175992693065336118205416902503",
"64634700976450262439933333199223582711",
"10580285920849808251762143147315374736",
"323739062134790674112277294049884128165"
],
"threshold": 0.9
},
"id": "ASB-A-237540408-8253a77c",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/frameworks/base/+/18f2ec86d680bff26ce9248061878894ad16e05f",
"target": {
"file": "services/core/java/com/android/server/notification/NotificationManagerService.java"
}
}
],
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/18f2ec86d680bff26ce9248061878894ad16e05f"
]
}{
"severity": "High",
"spl": "2022-11-01",
"vanir_signatures": [
{
"signature_type": "Function",
"digest": {
"length": 3197.0,
"function_hash": "246213615877169029966090081243936282525"
},
"id": "ASB-A-237540408-47554d02",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/frameworks/base/+/a367c0a16a9070ed6bee3028ac5bbc967773ee8f",
"target": {
"file": "services/core/java/com/android/server/notification/NotificationManagerService.java",
"function": "buzzBeepBlinkLocked"
}
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"323724515043905430543994376006462360177",
"115894979338096264011054995498352607437",
"1470757861002783157935506182797325807",
"314131693363967520025389527100311765605"
],
"threshold": 0.9
},
"id": "ASB-A-237540408-e93623d6",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/frameworks/base/+/a367c0a16a9070ed6bee3028ac5bbc967773ee8f",
"target": {
"file": "services/core/java/com/android/server/notification/NotificationManagerService.java"
}
}
],
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/a367c0a16a9070ed6bee3028ac5bbc967773ee8f"
]
}{
"severity": "High",
"spl": "2022-11-01",
"vanir_signatures": [
{
"signature_type": "Function",
"digest": {
"length": 3197.0,
"function_hash": "246213615877169029966090081243936282525"
},
"id": "ASB-A-237540408-401edd44",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/frameworks/base/+/a367c0a16a9070ed6bee3028ac5bbc967773ee8f",
"target": {
"file": "services/core/java/com/android/server/notification/NotificationManagerService.java",
"function": "buzzBeepBlinkLocked"
}
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"323724515043905430543994376006462360177",
"115894979338096264011054995498352607437",
"1470757861002783157935506182797325807",
"314131693363967520025389527100311765605"
],
"threshold": 0.9
},
"id": "ASB-A-237540408-faef40a3",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/frameworks/base/+/a367c0a16a9070ed6bee3028ac5bbc967773ee8f",
"target": {
"file": "services/core/java/com/android/server/notification/NotificationManagerService.java"
}
}
],
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/a367c0a16a9070ed6bee3028ac5bbc967773ee8f"
]
}{
"severity": "High",
"spl": "2022-11-01",
"vanir_signatures": [
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"323724515043905430543994376006462360177",
"115894979338096264011054995498352607437",
"1470757861002783157935506182797325807",
"314131693363967520025389527100311765605"
],
"threshold": 0.9
},
"id": "ASB-A-237540408-1d3148a0",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/frameworks/base/+/a367c0a16a9070ed6bee3028ac5bbc967773ee8f",
"target": {
"file": "services/core/java/com/android/server/notification/NotificationManagerService.java"
}
},
{
"signature_type": "Function",
"digest": {
"length": 3197.0,
"function_hash": "246213615877169029966090081243936282525"
},
"id": "ASB-A-237540408-473e2f41",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/frameworks/base/+/a367c0a16a9070ed6bee3028ac5bbc967773ee8f",
"target": {
"file": "services/core/java/com/android/server/notification/NotificationManagerService.java",
"function": "buzzBeepBlinkLocked"
}
}
],
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/a367c0a16a9070ed6bee3028ac5bbc967773ee8f"
]
}{
"severity": "High",
"spl": "2022-11-01",
"vanir_signatures": [
{
"signature_type": "Function",
"digest": {
"length": 3197.0,
"function_hash": "246213615877169029966090081243936282525"
},
"id": "ASB-A-237540408-0d6a8f7e",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/frameworks/base/+/a367c0a16a9070ed6bee3028ac5bbc967773ee8f",
"target": {
"file": "services/core/java/com/android/server/notification/NotificationManagerService.java",
"function": "buzzBeepBlinkLocked"
}
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"323724515043905430543994376006462360177",
"115894979338096264011054995498352607437",
"1470757861002783157935506182797325807",
"314131693363967520025389527100311765605"
],
"threshold": 0.9
},
"id": "ASB-A-237540408-f0251864",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/frameworks/base/+/a367c0a16a9070ed6bee3028ac5bbc967773ee8f",
"target": {
"file": "services/core/java/com/android/server/notification/NotificationManagerService.java"
}
}
],
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/a367c0a16a9070ed6bee3028ac5bbc967773ee8f"
]
}