In update of MmsProvider.java, there is a possible way to bypass file permission checks due to a race condition. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "length": 2447.0, "function_hash": "157104286834053058667808334963109926916" }, "id": "ASB-A-264880689-684bfacc", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsProvider.java", "function": "update" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "281253907639525144025299373930782407033", "132876137314617094737140570055861165390", "4690526999091256758990293462794369238", "7544939645273274879206324847218671046", "12071255814901493088040976794853679443", "164998211426005178073519557115678279380", "224677706242864877018902563102024141642", "33215650706164921697314748434731617263", "123209350887477386788433845434072400276", "9931110887952007559812108128041600154", "214728215846428908470951434899761443372", "278832171060732843206969616038814260467" ] }, "id": "ASB-A-264880689-dfbed74f", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsProvider.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c" ], "spl": "2023-08-01", "severity": "High", "types": [ "DoS" ] }
{ "vanir_signatures": [ { "digest": { "length": 2447.0, "function_hash": "157104286834053058667808334963109926916" }, "id": "ASB-A-264880689-0825b9fe", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsProvider.java", "function": "update" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "281253907639525144025299373930782407033", "132876137314617094737140570055861165390", "4690526999091256758990293462794369238", "7544939645273274879206324847218671046", "12071255814901493088040976794853679443", "164998211426005178073519557115678279380", "224677706242864877018902563102024141642", "33215650706164921697314748434731617263", "123209350887477386788433845434072400276", "9931110887952007559812108128041600154", "214728215846428908470951434899761443372", "278832171060732843206969616038814260467" ] }, "id": "ASB-A-264880689-8bbb028b", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsProvider.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c" ], "spl": "2023-08-01", "severity": "High", "types": [ "DoS" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "281253907639525144025299373930782407033", "132876137314617094737140570055861165390", "4690526999091256758990293462794369238", "7544939645273274879206324847218671046", "12071255814901493088040976794853679443", "164998211426005178073519557115678279380", "224677706242864877018902563102024141642", "33215650706164921697314748434731617263", "123209350887477386788433845434072400276", "9931110887952007559812108128041600154", "214728215846428908470951434899761443372", "278832171060732843206969616038814260467" ] }, "id": "ASB-A-264880689-65fd960f", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsProvider.java" }, "signature_type": "Line" }, { "digest": { "length": 2447.0, "function_hash": "157104286834053058667808334963109926916" }, "id": "ASB-A-264880689-8d4acadd", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsProvider.java", "function": "update" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c" ], "spl": "2023-08-01", "severity": "High", "types": [ "DoS" ] }
{ "vanir_signatures": [ { "digest": { "length": 2447.0, "function_hash": "157104286834053058667808334963109926916" }, "id": "ASB-A-264880689-bd1a1eaf", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsProvider.java", "function": "update" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "281253907639525144025299373930782407033", "132876137314617094737140570055861165390", "4690526999091256758990293462794369238", "7544939645273274879206324847218671046", "12071255814901493088040976794853679443", "164998211426005178073519557115678279380", "224677706242864877018902563102024141642", "33215650706164921697314748434731617263", "123209350887477386788433845434072400276", "9931110887952007559812108128041600154", "214728215846428908470951434899761443372", "278832171060732843206969616038814260467" ] }, "id": "ASB-A-264880689-c4fc9a17", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsProvider.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c" ], "spl": "2023-08-01", "severity": "High", "types": [ "DoS" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "281253907639525144025299373930782407033", "132876137314617094737140570055861165390", "4690526999091256758990293462794369238", "7544939645273274879206324847218671046", "12071255814901493088040976794853679443", "164998211426005178073519557115678279380", "224677706242864877018902563102024141642", "33215650706164921697314748434731617263", "123209350887477386788433845434072400276", "9931110887952007559812108128041600154", "214728215846428908470951434899761443372", "278832171060732843206969616038814260467" ] }, "id": "ASB-A-264880689-78ae990a", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsProvider.java" }, "signature_type": "Line" }, { "digest": { "length": 2447.0, "function_hash": "157104286834053058667808334963109926916" }, "id": "ASB-A-264880689-fdc3403f", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsProvider.java", "function": "update" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c" ], "spl": "2023-08-01", "severity": "High", "types": [ "DoS" ] }