In multiple functions of extents.c, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "320798409341611166830814108508150255871", "112857772578265157077974853171378863860", "51319408034959105330974098697356017529", "62227709865264296650074501689090221646", "89496045483948728382626014586875216797", "110022765742622761164213413285828158164", "184586808288376308298158792635999809476", "127359033965561290498045986322230088270", "194799918441195152958042076887609734007", "266555255397832427611064751693224850387", "62120813187215708036004986929357462327", "203296511091826565336955712105399805879" ] }, "id": "ASB-A-245406696-163502d4", "source": "https://android.googlesource.com/kernel/common/+/ce3aba43599f0", "deprecated": false, "signature_version": "v1", "target": { "file": "fs/ext4/extents.c" }, "signature_type": "Line" }, { "digest": { "length": 257.0, "function_hash": "108512274644312616448934776004964943115" }, "id": "ASB-A-245406696-a64c2384", "source": "https://android.googlesource.com/kernel/common/+/ce3aba43599f0", "deprecated": false, "signature_version": "v1", "target": { "file": "fs/ext4/extents.c", "function": "ext4_ext_tree_init" }, "signature_type": "Function" }, { "digest": { "length": 5166.0, "function_hash": "208517607189020705050717253614082309300" }, "id": "ASB-A-245406696-ba082be7", "source": "https://android.googlesource.com/kernel/common/+/ce3aba43599f0", "deprecated": false, "signature_version": "v1", "target": { "file": "fs/ext4/extents.c", "function": "ext4_ext_split" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/kernel/common/+/ce3aba43599f0" ], "spl": "2023-02-05", "severity": "High", "types": [ "ID" ] }