In multiple locations, there is a possible way to crash multiple system services due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
],
"vanir_signatures": [
{
"digest": {
"length": 345.0,
"function_hash": "249915354582923191798266077908697072256"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-202659be",
"target": {
"function": "readCertificates",
"file": "core/java/android/util/jar/StrictJarVerifier.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
},
{
"digest": {
"length": 1375.0,
"function_hash": "76378410095532720956002145985191073570"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-25e19998",
"target": {
"function": "verify",
"file": "core/java/android/util/apk/ApkSignatureSchemeV2Verifier.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"127591183906428000100661990238153668826",
"240609319350722928473919306482041019539",
"291486844225277494726308172124066601464",
"119807339177862674962200230646681423358",
"9564776611380162473768305298920529708",
"187258210791204064424156638109163959388",
"311698033013677502681369731221858027212"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-30e18f3b",
"target": {
"file": "core/java/android/util/apk/ApkSignatureSchemeV2Verifier.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"129744209502793915813260619052832012600",
"264113637825344716206162844253084270500",
"30215904757720273077659302057981667921",
"299631063491229373266064701101652182332",
"237790250428028202705881335151452949033",
"39096619547947512736311842163264836793",
"265640756765803956838572199192976623552",
"267676677489576409428264675310911676797",
"200840196954250196286453188352233489228",
"119046298690815096111332514719412588051"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-3fd3dd04",
"target": {
"file": "core/java/android/util/jar/StrictJarVerifier.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
}
],
"types": [
"DoS"
],
"spl": "2023-10-01",
"severity": "High"
}{
"fixes": [
"https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
],
"vanir_signatures": [
{
"digest": {
"length": 726.0,
"function_hash": "213318869695566115113803252493268411376"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-48a1aade",
"target": {
"function": "generateApkSignatureSchemeV2Block",
"file": "src/main/java/com/android/apksig/internal/apk/v2/V2SchemeSigner.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"12618301161831551205318197541620737508",
"98755959483069616998261581973137485491",
"90902607722267191119850184141701387206",
"320695860838695213398059869796611028816",
"156083528888115917432528088227340568869"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-51c47a48",
"target": {
"file": "src/main/java/com/android/apksig/internal/apk/v1/V1SchemeSigner.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"90172167375156212023865176702410805323",
"255828293149117205601751866485063807101",
"283147441159775087592892492815682190961",
"281741627391602248632793172452235808643",
"161160446596792945093007825717673037311",
"224284982970141525191405149060650164069",
"281423487149610749286690012279529074670",
"329054542011880781089773095494031838405"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-54b753dc",
"target": {
"file": "src/main/java/com/android/apksig/internal/apk/v2/V2SchemeSigner.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"166308627250241798830278720308157210028",
"204021523883075718267869134804624054837",
"293949540968280903538352693917672011553",
"125492843029688495070507629923640435993",
"310355743575466778701922714034586285378"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-7f72a0a9",
"target": {
"file": "src/main/java/com/android/apksig/internal/apk/v2/V2SchemeVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"318259293619017571817674845858708848436",
"127079537267571699098745376265682096815",
"139115357152174844383564699394576699834"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-ac369905",
"target": {
"file": "src/main/java/com/android/apksig/Constants.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
},
{
"digest": {
"length": 433.0,
"function_hash": "22470244999601055631616563743597494561"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-b1490b3a",
"target": {
"function": "sign",
"file": "src/main/java/com/android/apksig/internal/apk/v1/V1SchemeSigner.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"138091845747979162666087952714147299396",
"251139346529762752694104483570799064211",
"199102190805175363047783006961641316782",
"160564518559890903662277250347960425158",
"14955106898394308134487221076974122598"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-bc81e2f0",
"target": {
"file": "src/main/java/com/android/apksig/internal/apk/v1/V1SchemeVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
},
{
"digest": {
"length": 991.0,
"function_hash": "222328988143613824287965131789779771686"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-d4e4922e",
"target": {
"function": "parseSigners",
"file": "src/main/java/com/android/apksig/internal/apk/v2/V2SchemeVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"195323898097579571440473038818311772522",
"85927087583516576559657909816730739506",
"126594930388151554529098213431576280383",
"257815311357202562710622069557207829188",
"33966035226034354764799743487013125884",
"213804718474314383533809336886931483632"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-d5c71974",
"target": {
"file": "src/main/java/com/android/apksig/ApkVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
},
{
"digest": {
"length": 3495.0,
"function_hash": "262962228558343875874916341515667901288"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-f5a38546",
"target": {
"function": "verify",
"file": "src/main/java/com/android/apksig/internal/apk/v1/V1SchemeVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
}
],
"types": [
"DoS"
],
"spl": "2023-10-01",
"severity": "High"
}{
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
],
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"127591183906428000100661990238153668826",
"240609319350722928473919306482041019539",
"291486844225277494726308172124066601464",
"119807339177862674962200230646681423358",
"9564776611380162473768305298920529708",
"187258210791204064424156638109163959388",
"311698033013677502681369731221858027212"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-26d2a5b7",
"target": {
"file": "core/java/android/util/apk/ApkSignatureSchemeV2Verifier.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"129744209502793915813260619052832012600",
"264113637825344716206162844253084270500",
"30215904757720273077659302057981667921",
"299631063491229373266064701101652182332",
"237790250428028202705881335151452949033",
"39096619547947512736311842163264836793",
"265640756765803956838572199192976623552",
"267676677489576409428264675310911676797",
"200840196954250196286453188352233489228",
"119046298690815096111332514719412588051"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-781cbf9d",
"target": {
"file": "core/java/android/util/jar/StrictJarVerifier.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
},
{
"digest": {
"length": 345.0,
"function_hash": "249915354582923191798266077908697072256"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-d847131d",
"target": {
"function": "readCertificates",
"file": "core/java/android/util/jar/StrictJarVerifier.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
},
{
"digest": {
"length": 1375.0,
"function_hash": "76378410095532720956002145985191073570"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-e1982cab",
"target": {
"function": "verify",
"file": "core/java/android/util/apk/ApkSignatureSchemeV2Verifier.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
}
],
"types": [
"DoS"
],
"spl": "2023-10-01",
"severity": "High"
}{
"fixes": [
"https://android.googlesource.com/platform/tools/apksig/+/080e4039aeeca5d0ed55049dcfd3915e4d649239"
],
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"166308627250241798830278720308157210028",
"204021523883075718267869134804624054837",
"293949540968280903538352693917672011553",
"125492843029688495070507629923640435993",
"310355743575466778701922714034586285378"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-08d66403",
"target": {
"file": "src/main/java/com/android/apksig/internal/apk/v2/V2SchemeVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/080e4039aeeca5d0ed55049dcfd3915e4d649239"
},
{
"digest": {
"length": 991.0,
"function_hash": "222328988143613824287965131789779771686"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-4ebe82aa",
"target": {
"function": "parseSigners",
"file": "src/main/java/com/android/apksig/internal/apk/v2/V2SchemeVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/080e4039aeeca5d0ed55049dcfd3915e4d649239"
},
{
"digest": {
"length": 433.0,
"function_hash": "22470244999601055631616563743597494561"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-5edc31c2",
"target": {
"function": "sign",
"file": "src/main/java/com/android/apksig/internal/apk/v1/V1SchemeSigner.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/080e4039aeeca5d0ed55049dcfd3915e4d649239"
},
{
"digest": {
"length": 3475.0,
"function_hash": "333444367386528009047836502053223450042"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-76928673",
"target": {
"function": "verify",
"file": "src/main/java/com/android/apksig/internal/apk/v1/V1SchemeVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/080e4039aeeca5d0ed55049dcfd3915e4d649239"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"90172167375156212023865176702410805323",
"255828293149117205601751866485063807101",
"283147441159775087592892492815682190961",
"281741627391602248632793172452235808643",
"161160446596792945093007825717673037311",
"19318538246823043399536733526229174470",
"339695200048526063472714976939320224941",
"117245178116164655333834700469779125972"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-947541b1",
"target": {
"file": "src/main/java/com/android/apksig/internal/apk/v2/V2SchemeSigner.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/080e4039aeeca5d0ed55049dcfd3915e4d649239"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"37533447064962364212589698078441805597",
"98755959483069616998261581973137485491",
"90902607722267191119850184141701387206",
"320695860838695213398059869796611028816",
"156083528888115917432528088227340568869"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-bbcae137",
"target": {
"file": "src/main/java/com/android/apksig/internal/apk/v1/V1SchemeSigner.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/080e4039aeeca5d0ed55049dcfd3915e4d649239"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"47428040235981702453145689256894068721",
"12672754703303928234164998712563517569",
"8610655643251529581441854087647599748",
"249434984663158798916763270884250273655",
"195323898097579571440473038818311772522",
"85927087583516576559657909816730739506",
"126594930388151554529098213431576280383",
"257815311357202562710622069557207829188",
"33966035226034354764799743487013125884",
"213804718474314383533809336886931483632"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-cdd30be9",
"target": {
"file": "src/main/java/com/android/apksig/ApkVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/080e4039aeeca5d0ed55049dcfd3915e4d649239"
},
{
"digest": {
"length": 612.0,
"function_hash": "87843026847037016839933472380593091061"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-d45a768e",
"target": {
"function": "generateApkSignatureSchemeV2Block",
"file": "src/main/java/com/android/apksig/internal/apk/v2/V2SchemeSigner.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/080e4039aeeca5d0ed55049dcfd3915e4d649239"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"138091845747979162666087952714147299396",
"251139346529762752694104483570799064211",
"199102190805175363047783006961641316782",
"160564518559890903662277250347960425158",
"14955106898394308134487221076974122598"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-de1d0fc3",
"target": {
"file": "src/main/java/com/android/apksig/internal/apk/v1/V1SchemeVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/080e4039aeeca5d0ed55049dcfd3915e4d649239"
},
{
"digest": {
"length": 1169.0,
"function_hash": "220020544393900911384356231346521659494"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-fe6d3c49",
"target": {
"function": "mergeFrom",
"file": "src/main/java/com/android/apksig/ApkVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/080e4039aeeca5d0ed55049dcfd3915e4d649239"
}
],
"types": [
"DoS"
],
"spl": "2023-10-01",
"severity": "High"
}{
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
],
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"127591183906428000100661990238153668826",
"240609319350722928473919306482041019539",
"291486844225277494726308172124066601464",
"119807339177862674962200230646681423358",
"9564776611380162473768305298920529708",
"187258210791204064424156638109163959388",
"311698033013677502681369731221858027212"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-2dffb6d8",
"target": {
"file": "core/java/android/util/apk/ApkSignatureSchemeV2Verifier.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
},
{
"digest": {
"length": 345.0,
"function_hash": "249915354582923191798266077908697072256"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-62ba78f6",
"target": {
"function": "readCertificates",
"file": "core/java/android/util/jar/StrictJarVerifier.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
},
{
"digest": {
"length": 1375.0,
"function_hash": "76378410095532720956002145985191073570"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-7d3cb9ae",
"target": {
"function": "verify",
"file": "core/java/android/util/apk/ApkSignatureSchemeV2Verifier.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"129744209502793915813260619052832012600",
"264113637825344716206162844253084270500",
"30215904757720273077659302057981667921",
"299631063491229373266064701101652182332",
"237790250428028202705881335151452949033",
"39096619547947512736311842163264836793",
"265640756765803956838572199192976623552",
"267676677489576409428264675310911676797",
"200840196954250196286453188352233489228",
"119046298690815096111332514719412588051"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-939c829d",
"target": {
"file": "core/java/android/util/jar/StrictJarVerifier.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
}
],
"types": [
"DoS"
],
"spl": "2023-10-01",
"severity": "High"
}{
"fixes": [
"https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
],
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"166308627250241798830278720308157210028",
"204021523883075718267869134804624054837",
"293949540968280903538352693917672011553",
"125492843029688495070507629923640435993",
"310355743575466778701922714034586285378"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-38ae67da",
"target": {
"file": "src/main/java/com/android/apksig/internal/apk/v2/V2SchemeVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"83835231554199575221028493457154853768",
"187526407930162239029248123558231366877",
"139115357152174844383564699394576699834"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-413fe738",
"target": {
"file": "src/main/java/com/android/apksig/Constants.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"138091845747979162666087952714147299396",
"251139346529762752694104483570799064211",
"199102190805175363047783006961641316782",
"160564518559890903662277250347960425158",
"14955106898394308134487221076974122598"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-57b1d910",
"target": {
"file": "src/main/java/com/android/apksig/internal/apk/v1/V1SchemeVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
},
{
"digest": {
"length": 632.0,
"function_hash": "114059583829668587052886837139387282040"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-5b0e97b8",
"target": {
"function": "generateApkSignatureSchemeV2Block",
"file": "src/main/java/com/android/apksig/internal/apk/v2/V2SchemeSigner.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
},
{
"digest": {
"length": 991.0,
"function_hash": "222328988143613824287965131789779771686"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-82e25833",
"target": {
"function": "parseSigners",
"file": "src/main/java/com/android/apksig/internal/apk/v2/V2SchemeVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
},
{
"digest": {
"length": 433.0,
"function_hash": "22470244999601055631616563743597494561"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-99a609ef",
"target": {
"function": "sign",
"file": "src/main/java/com/android/apksig/internal/apk/v1/V1SchemeSigner.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"37533447064962364212589698078441805597",
"98755959483069616998261581973137485491",
"90902607722267191119850184141701387206",
"320695860838695213398059869796611028816",
"156083528888115917432528088227340568869"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-ac1266e9",
"target": {
"file": "src/main/java/com/android/apksig/internal/apk/v1/V1SchemeSigner.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
},
{
"digest": {
"length": 1075.0,
"function_hash": "59115683397571627065104435808932691233"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-b17e6b25",
"target": {
"function": "mergeFrom",
"file": "src/main/java/com/android/apksig/ApkVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"166660708084919229288884510559300593615",
"12672754703303928234164998712563517569",
"8610655643251529581441854087647599748",
"249434984663158798916763270884250273655",
"195323898097579571440473038818311772522",
"85927087583516576559657909816730739506",
"126594930388151554529098213431576280383",
"257815311357202562710622069557207829188",
"33966035226034354764799743487013125884",
"213804718474314383533809336886931483632"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-b4868a3c",
"target": {
"file": "src/main/java/com/android/apksig/ApkVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"90172167375156212023865176702410805323",
"255828293149117205601751866485063807101",
"283147441159775087592892492815682190961",
"281741627391602248632793172452235808643",
"161160446596792945093007825717673037311",
"19318538246823043399536733526229174470",
"339695200048526063472714976939320224941",
"117245178116164655333834700469779125972"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-ea78f0ff",
"target": {
"file": "src/main/java/com/android/apksig/internal/apk/v2/V2SchemeSigner.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
},
{
"digest": {
"length": 3495.0,
"function_hash": "262962228558343875874916341515667901288"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-f39328b0",
"target": {
"function": "verify",
"file": "src/main/java/com/android/apksig/internal/apk/v1/V1SchemeVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
}
],
"types": [
"DoS"
],
"spl": "2023-10-01",
"severity": "High"
}{
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
],
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"129744209502793915813260619052832012600",
"264113637825344716206162844253084270500",
"30215904757720273077659302057981667921",
"299631063491229373266064701101652182332",
"237790250428028202705881335151452949033",
"39096619547947512736311842163264836793",
"265640756765803956838572199192976623552",
"267676677489576409428264675310911676797",
"200840196954250196286453188352233489228",
"119046298690815096111332514719412588051"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-41403806",
"target": {
"file": "core/java/android/util/jar/StrictJarVerifier.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
},
{
"digest": {
"length": 345.0,
"function_hash": "249915354582923191798266077908697072256"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-52f0a788",
"target": {
"function": "readCertificates",
"file": "core/java/android/util/jar/StrictJarVerifier.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"127591183906428000100661990238153668826",
"240609319350722928473919306482041019539",
"291486844225277494726308172124066601464",
"119807339177862674962200230646681423358",
"9564776611380162473768305298920529708",
"187258210791204064424156638109163959388",
"311698033013677502681369731221858027212"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-58a326c2",
"target": {
"file": "core/java/android/util/apk/ApkSignatureSchemeV2Verifier.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
},
{
"digest": {
"length": 1375.0,
"function_hash": "76378410095532720956002145985191073570"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-5e42fe1a",
"target": {
"function": "verify",
"file": "core/java/android/util/apk/ApkSignatureSchemeV2Verifier.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
}
],
"types": [
"DoS"
],
"spl": "2023-10-01",
"severity": "High"
}{
"fixes": [
"https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
],
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"37533447064962364212589698078441805597",
"98755959483069616998261581973137485491",
"90902607722267191119850184141701387206",
"320695860838695213398059869796611028816",
"156083528888115917432528088227340568869"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-43be5085",
"target": {
"file": "src/main/java/com/android/apksig/internal/apk/v1/V1SchemeSigner.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
},
{
"digest": {
"length": 433.0,
"function_hash": "22470244999601055631616563743597494561"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-578205df",
"target": {
"function": "sign",
"file": "src/main/java/com/android/apksig/internal/apk/v1/V1SchemeSigner.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
},
{
"digest": {
"length": 1075.0,
"function_hash": "59115683397571627065104435808932691233"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-5f8b084b",
"target": {
"function": "mergeFrom",
"file": "src/main/java/com/android/apksig/ApkVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"138091845747979162666087952714147299396",
"251139346529762752694104483570799064211",
"199102190805175363047783006961641316782",
"160564518559890903662277250347960425158",
"14955106898394308134487221076974122598"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-62e4fb30",
"target": {
"file": "src/main/java/com/android/apksig/internal/apk/v1/V1SchemeVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"90172167375156212023865176702410805323",
"255828293149117205601751866485063807101",
"283147441159775087592892492815682190961",
"281741627391602248632793172452235808643",
"161160446596792945093007825717673037311",
"19318538246823043399536733526229174470",
"339695200048526063472714976939320224941",
"117245178116164655333834700469779125972"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-672f0d32",
"target": {
"file": "src/main/java/com/android/apksig/internal/apk/v2/V2SchemeSigner.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
},
{
"digest": {
"length": 3495.0,
"function_hash": "262962228558343875874916341515667901288"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-7984f14e",
"target": {
"function": "verify",
"file": "src/main/java/com/android/apksig/internal/apk/v1/V1SchemeVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
},
{
"digest": {
"length": 632.0,
"function_hash": "114059583829668587052886837139387282040"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-7a25ca3b",
"target": {
"function": "generateApkSignatureSchemeV2Block",
"file": "src/main/java/com/android/apksig/internal/apk/v2/V2SchemeSigner.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"83835231554199575221028493457154853768",
"187526407930162239029248123558231366877",
"139115357152174844383564699394576699834"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-94c22bc5",
"target": {
"file": "src/main/java/com/android/apksig/Constants.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
},
{
"digest": {
"length": 991.0,
"function_hash": "222328988143613824287965131789779771686"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-a5aebea3",
"target": {
"function": "parseSigners",
"file": "src/main/java/com/android/apksig/internal/apk/v2/V2SchemeVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"166660708084919229288884510559300593615",
"12672754703303928234164998712563517569",
"8610655643251529581441854087647599748",
"249434984663158798916763270884250273655",
"195323898097579571440473038818311772522",
"85927087583516576559657909816730739506",
"126594930388151554529098213431576280383",
"257815311357202562710622069557207829188",
"33966035226034354764799743487013125884",
"213804718474314383533809336886931483632"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-cf4326bc",
"target": {
"file": "src/main/java/com/android/apksig/ApkVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"166308627250241798830278720308157210028",
"204021523883075718267869134804624054837",
"293949540968280903538352693917672011553",
"125492843029688495070507629923640435993",
"310355743575466778701922714034586285378"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-e9923eca",
"target": {
"file": "src/main/java/com/android/apksig/internal/apk/v2/V2SchemeVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/dae412630054cc9ec19ec03e0e827585e619f6ac"
}
],
"types": [
"DoS"
],
"spl": "2023-10-01",
"severity": "High"
}{
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
],
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"127591183906428000100661990238153668826",
"240609319350722928473919306482041019539",
"291486844225277494726308172124066601464",
"119807339177862674962200230646681423358",
"9564776611380162473768305298920529708",
"187258210791204064424156638109163959388",
"311698033013677502681369731221858027212"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-15af2d2b",
"target": {
"file": "core/java/android/util/apk/ApkSignatureSchemeV2Verifier.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
},
{
"digest": {
"length": 345.0,
"function_hash": "249915354582923191798266077908697072256"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-298ab3f0",
"target": {
"function": "readCertificates",
"file": "core/java/android/util/jar/StrictJarVerifier.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
},
{
"digest": {
"length": 1375.0,
"function_hash": "76378410095532720956002145985191073570"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-56ef6703",
"target": {
"function": "verify",
"file": "core/java/android/util/apk/ApkSignatureSchemeV2Verifier.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"129744209502793915813260619052832012600",
"264113637825344716206162844253084270500",
"30215904757720273077659302057981667921",
"299631063491229373266064701101652182332",
"237790250428028202705881335151452949033",
"39096619547947512736311842163264836793",
"265640756765803956838572199192976623552",
"267676677489576409428264675310911676797",
"200840196954250196286453188352233489228",
"119046298690815096111332514719412588051"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-aa02e7bf",
"target": {
"file": "core/java/android/util/jar/StrictJarVerifier.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6f6ee8a55f37c2b8c0df041b2bd53ec928764597"
}
],
"types": [
"DoS"
],
"spl": "2023-10-01",
"severity": "High"
}{
"fixes": [
"https://android.googlesource.com/platform/tools/apksig/+/0b086bdc130e1e6216fcbc5436fe8e3cdc9ec011",
"https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
],
"vanir_signatures": [
{
"digest": {
"length": 991.0,
"function_hash": "222328988143613824287965131789779771686"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-00c5b830",
"target": {
"function": "parseSigners",
"file": "src/main/java/com/android/apksig/internal/apk/v2/V2SchemeVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"195323898097579571440473038818311772522",
"85927087583516576559657909816730739506",
"126594930388151554529098213431576280383",
"257815311357202562710622069557207829188",
"33966035226034354764799743487013125884",
"213804718474314383533809336886931483632"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-07a97c2a",
"target": {
"file": "src/main/java/com/android/apksig/ApkVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"138091845747979162666087952714147299396",
"251139346529762752694104483570799064211",
"199102190805175363047783006961641316782",
"160564518559890903662277250347960425158",
"14955106898394308134487221076974122598"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-229c07d8",
"target": {
"file": "src/main/java/com/android/apksig/internal/apk/v1/V1SchemeVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
},
{
"digest": {
"length": 726.0,
"function_hash": "213318869695566115113803252493268411376"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-233bef49",
"target": {
"function": "generateApkSignatureSchemeV2Block",
"file": "src/main/java/com/android/apksig/internal/apk/v2/V2SchemeSigner.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"318259293619017571817674845858708848436",
"127079537267571699098745376265682096815",
"139115357152174844383564699394576699834"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-373ced3e",
"target": {
"file": "src/main/java/com/android/apksig/Constants.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
},
{
"digest": {
"length": 3495.0,
"function_hash": "262962228558343875874916341515667901288"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-5069b810",
"target": {
"function": "verify",
"file": "src/main/java/com/android/apksig/internal/apk/v1/V1SchemeVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
},
{
"digest": {
"length": 433.0,
"function_hash": "22470244999601055631616563743597494561"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "ASB-A-266580022-5868a7c5",
"target": {
"function": "sign",
"file": "src/main/java/com/android/apksig/internal/apk/v1/V1SchemeSigner.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"90172167375156212023865176702410805323",
"255828293149117205601751866485063807101",
"283147441159775087592892492815682190961",
"281741627391602248632793172452235808643",
"161160446596792945093007825717673037311",
"224284982970141525191405149060650164069",
"281423487149610749286690012279529074670",
"329054542011880781089773095494031838405"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-99859c46",
"target": {
"file": "src/main/java/com/android/apksig/internal/apk/v2/V2SchemeSigner.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"166308627250241798830278720308157210028",
"204021523883075718267869134804624054837",
"293949540968280903538352693917672011553",
"125492843029688495070507629923640435993",
"310355743575466778701922714034586285378"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-d0743968",
"target": {
"file": "src/main/java/com/android/apksig/internal/apk/v2/V2SchemeVerifier.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"12618301161831551205318197541620737508",
"98755959483069616998261581973137485491",
"90902607722267191119850184141701387206",
"320695860838695213398059869796611028816",
"156083528888115917432528088227340568869"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "ASB-A-266580022-e94d13ba",
"target": {
"file": "src/main/java/com/android/apksig/internal/apk/v1/V1SchemeSigner.java"
},
"source": "https://android.googlesource.com/platform/tools/apksig/+/6be64b9339c1dad28abf75b53d3866fd42f320d6"
}
],
"types": [
"DoS"
],
"spl": "2023-10-01",
"severity": "High"
}