In loadFromXml of ShortcutPackage.java, there is a possible crash on boot due to an uncaught exception. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/9b0dd514d29bbf986f1d1a3c6cebc2ef2bcf782e"
],
"severity": "High",
"spl": "2022-12-01",
"vanir_signatures": [
{
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-246540168-b21ebe2c",
"digest": {
"length": 1163.0,
"function_hash": "303307791426374916355773548631408145706"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/9b0dd514d29bbf986f1d1a3c6cebc2ef2bcf782e",
"signature_type": "Function",
"target": {
"file": "services/core/java/com/android/server/pm/ShortcutPackage.java",
"function": "loadFromXml"
}
},
{
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-246540168-c87b34dc",
"digest": {
"line_hashes": [
"34419333322541914813054904699286127292",
"12464633297697607084927863006138098181",
"178337061343133787076664750874546771501",
"119490588587155382841851979906465608031",
"219571269220090821969910062474873505339",
"48533088707302787240171646085345067499"
],
"threshold": 0.9
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/9b0dd514d29bbf986f1d1a3c6cebc2ef2bcf782e",
"signature_type": "Line",
"target": {
"file": "services/core/java/com/android/server/pm/ShortcutPackage.java"
}
}
],
"types": [
"DoS"
]
}{
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/a8fe41afb0a89979386ffd17213eb7b5f1c3739d"
],
"severity": "High",
"spl": "2022-12-01",
"vanir_signatures": [
{
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-246540168-70845aa7",
"digest": {
"length": 1163.0,
"function_hash": "303307791426374916355773548631408145706"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/a8fe41afb0a89979386ffd17213eb7b5f1c3739d",
"signature_type": "Function",
"target": {
"file": "services/core/java/com/android/server/pm/ShortcutPackage.java",
"function": "loadFromXml"
}
},
{
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-246540168-88518ba1",
"digest": {
"line_hashes": [
"34419333322541914813054904699286127292",
"12464633297697607084927863006138098181",
"178337061343133787076664750874546771501",
"119490588587155382841851979906465608031",
"219571269220090821969910062474873505339",
"48533088707302787240171646085345067499"
],
"threshold": 0.9
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/a8fe41afb0a89979386ffd17213eb7b5f1c3739d",
"signature_type": "Line",
"target": {
"file": "services/core/java/com/android/server/pm/ShortcutPackage.java"
}
}
],
"types": [
"DoS"
]
}{
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/36338a315218221e51c24a42e44c4f743d416f82"
],
"severity": "High",
"spl": "2022-12-01",
"vanir_signatures": [
{
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-246540168-241602ba",
"digest": {
"length": 1305.0,
"function_hash": "234566476942551792555054834701921045702"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/36338a315218221e51c24a42e44c4f743d416f82",
"signature_type": "Function",
"target": {
"file": "services/core/java/com/android/server/pm/ShortcutPackage.java",
"function": "loadFromXml"
}
},
{
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-246540168-79431f6c",
"digest": {
"line_hashes": [
"34419333322541914813054904699286127292",
"12464633297697607084927863006138098181",
"178337061343133787076664750874546771501",
"119490588587155382841851979906465608031",
"219571269220090821969910062474873505339",
"48533088707302787240171646085345067499"
],
"threshold": 0.9
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/36338a315218221e51c24a42e44c4f743d416f82",
"signature_type": "Line",
"target": {
"file": "services/core/java/com/android/server/pm/ShortcutPackage.java"
}
}
],
"types": [
"DoS"
]
}{
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/36338a315218221e51c24a42e44c4f743d416f82"
],
"severity": "High",
"spl": "2022-12-01",
"vanir_signatures": [
{
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-246540168-8f2ca78e",
"digest": {
"length": 1305.0,
"function_hash": "234566476942551792555054834701921045702"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/36338a315218221e51c24a42e44c4f743d416f82",
"signature_type": "Function",
"target": {
"file": "services/core/java/com/android/server/pm/ShortcutPackage.java",
"function": "loadFromXml"
}
},
{
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-246540168-b2d6378c",
"digest": {
"line_hashes": [
"34419333322541914813054904699286127292",
"12464633297697607084927863006138098181",
"178337061343133787076664750874546771501",
"119490588587155382841851979906465608031",
"219571269220090821969910062474873505339",
"48533088707302787240171646085345067499"
],
"threshold": 0.9
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/36338a315218221e51c24a42e44c4f743d416f82",
"signature_type": "Line",
"target": {
"file": "services/core/java/com/android/server/pm/ShortcutPackage.java"
}
}
],
"types": [
"DoS"
]
}{
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/5238a70be8c3348f9592de5e625f6311e4d51032"
],
"severity": "High",
"spl": "2022-12-01",
"vanir_signatures": [
{
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-246540168-6b98b4b5",
"digest": {
"line_hashes": [
"34419333322541914813054904699286127292",
"12464633297697607084927863006138098181",
"178337061343133787076664750874546771501",
"119490588587155382841851979906465608031",
"219571269220090821969910062474873505339",
"48533088707302787240171646085345067499"
],
"threshold": 0.9
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/5238a70be8c3348f9592de5e625f6311e4d51032",
"signature_type": "Line",
"target": {
"file": "services/core/java/com/android/server/pm/ShortcutPackage.java"
}
},
{
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-246540168-73182cb7",
"digest": {
"length": 1351.0,
"function_hash": "63506753563844308566678897586287669685"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/5238a70be8c3348f9592de5e625f6311e4d51032",
"signature_type": "Function",
"target": {
"file": "services/core/java/com/android/server/pm/ShortcutPackage.java",
"function": "loadFromXml"
}
}
],
"types": [
"DoS"
]
}