In parserCreate of xmlparse.c, there is a possible use after free that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "length": 2638.0, "function_hash": "241864677999275664780112028235468015180" }, "id": "ASB-A-255449293-34e3439f", "source": "https://android.googlesource.com/platform/external/expat/+/eb8f10fb1f4eb13c5a2ba1edbfd64b5f2a50ff4a", "deprecated": false, "signature_version": "v1", "target": { "file": "lib/xmlparse.c", "function": "parserCreate" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "226920422708811604153776438321752425920", "256028773478336621521363198644248115645", "103238438290887398710675692008040585033", "322242168469623392234752613650614084011" ] }, "id": "ASB-A-255449293-4a995bdb", "source": "https://android.googlesource.com/platform/external/expat/+/eb8f10fb1f4eb13c5a2ba1edbfd64b5f2a50ff4a", "deprecated": false, "signature_version": "v1", "target": { "file": "lib/xmlparse.c" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/external/expat/+/eb8f10fb1f4eb13c5a2ba1edbfd64b5f2a50ff4a" ], "spl": "2023-02-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "226920422708811604153776438321752425920", "256028773478336621521363198644248115645", "103238438290887398710675692008040585033", "322242168469623392234752613650614084011" ] }, "id": "ASB-A-255449293-6c6c442b", "source": "https://android.googlesource.com/platform/external/expat/+/6944d3ebed0d631c92fdc31098e751b13dd110ba", "deprecated": false, "signature_version": "v1", "target": { "file": "lib/xmlparse.c" }, "signature_type": "Line" }, { "digest": { "length": 2638.0, "function_hash": "241864677999275664780112028235468015180" }, "id": "ASB-A-255449293-79a13a08", "source": "https://android.googlesource.com/platform/external/expat/+/6944d3ebed0d631c92fdc31098e751b13dd110ba", "deprecated": false, "signature_version": "v1", "target": { "file": "lib/xmlparse.c", "function": "parserCreate" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/external/expat/+/6944d3ebed0d631c92fdc31098e751b13dd110ba" ], "spl": "2023-02-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 2638.0, "function_hash": "241864677999275664780112028235468015180" }, "id": "ASB-A-255449293-51856fe7", "source": "https://android.googlesource.com/platform/external/expat/+/33765f82b29f6c1c5cecbbb8cf9dbd7327b3a93a", "deprecated": false, "signature_version": "v1", "target": { "file": "lib/xmlparse.c", "function": "parserCreate" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "226920422708811604153776438321752425920", "256028773478336621521363198644248115645", "103238438290887398710675692008040585033", "322242168469623392234752613650614084011" ] }, "id": "ASB-A-255449293-f813a8a7", "source": "https://android.googlesource.com/platform/external/expat/+/33765f82b29f6c1c5cecbbb8cf9dbd7327b3a93a", "deprecated": false, "signature_version": "v1", "target": { "file": "lib/xmlparse.c" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/external/expat/+/33765f82b29f6c1c5cecbbb8cf9dbd7327b3a93a" ], "spl": "2023-02-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "226920422708811604153776438321752425920", "256028773478336621521363198644248115645", "103238438290887398710675692008040585033", "322242168469623392234752613650614084011" ] }, "id": "ASB-A-255449293-65cf5b47", "source": "https://android.googlesource.com/platform/external/expat/+/9b0f62fd0f75a5dd555e882b8f8bd2075723ea70", "deprecated": false, "signature_version": "v1", "target": { "file": "lib/xmlparse.c" }, "signature_type": "Line" }, { "digest": { "length": 2638.0, "function_hash": "241864677999275664780112028235468015180" }, "id": "ASB-A-255449293-7f0cb565", "source": "https://android.googlesource.com/platform/external/expat/+/9b0f62fd0f75a5dd555e882b8f8bd2075723ea70", "deprecated": false, "signature_version": "v1", "target": { "file": "lib/xmlparse.c", "function": "parserCreate" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/external/expat/+/9b0f62fd0f75a5dd555e882b8f8bd2075723ea70" ], "spl": "2023-02-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 2628.0, "function_hash": "312759231179727010765375572738949972618" }, "id": "ASB-A-255449293-0e9ebc85", "source": "https://android.googlesource.com/platform/external/expat/+/63727cb0b8bdba580f5be48f7260e6e08fea5a5a", "deprecated": false, "signature_version": "v1", "target": { "file": "lib/xmlparse.c", "function": "parserCreate" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "226920422708811604153776438321752425920", "256028773478336621521363198644248115645", "103238438290887398710675692008040585033", "322242168469623392234752613650614084011" ] }, "id": "ASB-A-255449293-955c0572", "source": "https://android.googlesource.com/platform/external/expat/+/63727cb0b8bdba580f5be48f7260e6e08fea5a5a", "deprecated": false, "signature_version": "v1", "target": { "file": "lib/xmlparse.c" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/external/expat/+/63727cb0b8bdba580f5be48f7260e6e08fea5a5a" ], "spl": "2023-02-01", "severity": "High", "types": [ "EoP" ] }