In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"function_hash": "138989191116497150192229991517836027203",
"length": 3934.0
},
"id": "ASB-A-299441833-38709f53",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/base/+/496e78a1951f2ed69290f03c5625c0f8382f4d31",
"deprecated": false,
"target": {
"function": "installExistingPackageAsUser",
"file": "services/core/java/com/android/server/pm/InstallPackageHelper.java"
},
"signature_version": "v1"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"223414134673961314150758707332884666599",
"297832111914664628625290241149198251561",
"200773103184735589871286713125911464428",
"328687726879581702857568231538760663042"
]
},
"id": "ASB-A-299441833-f557e68b",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/base/+/496e78a1951f2ed69290f03c5625c0f8382f4d31",
"deprecated": false,
"target": {
"file": "services/core/java/com/android/server/pm/InstallPackageHelper.java"
},
"signature_version": "v1"
}
],
"types": [
"EoP"
],
"spl": "2024-03-01",
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/496e78a1951f2ed69290f03c5625c0f8382f4d31"
],
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"305309295635932314604993172670275855343",
"155395927358001145444523690570857776417",
"278129988737214380373573150486364105084",
"203617683842027651818499204898684772928"
]
},
"id": "ASB-A-299441833-4b126c86",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/base/+/0d0f185c0d526c1dac0a8894b2c2f2e378328d73",
"deprecated": false,
"target": {
"file": "services/core/java/com/android/server/pm/PackageManagerService.java"
},
"signature_version": "v1"
},
{
"digest": {
"function_hash": "149833891819253482617684091928861207008",
"length": 3062.0
},
"id": "ASB-A-299441833-8338fbd7",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/base/+/0d0f185c0d526c1dac0a8894b2c2f2e378328d73",
"deprecated": false,
"target": {
"function": "installExistingPackageAsUser",
"file": "services/core/java/com/android/server/pm/PackageManagerService.java"
},
"signature_version": "v1"
}
],
"types": [
"EoP"
],
"spl": "2024-03-01",
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/0d0f185c0d526c1dac0a8894b2c2f2e378328d73"
],
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"function_hash": "149833891819253482617684091928861207008",
"length": 3062.0
},
"id": "ASB-A-299441833-4764aff6",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/base/+/fbdeb248db7dee192392d82fe15482760b8af941",
"deprecated": false,
"target": {
"function": "installExistingPackageAsUser",
"file": "services/core/java/com/android/server/pm/PackageManagerService.java"
},
"signature_version": "v1"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"305309295635932314604993172670275855343",
"155395927358001145444523690570857776417",
"278129988737214380373573150486364105084",
"203617683842027651818499204898684772928"
]
},
"id": "ASB-A-299441833-bc1dc195",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/base/+/fbdeb248db7dee192392d82fe15482760b8af941",
"deprecated": false,
"target": {
"file": "services/core/java/com/android/server/pm/PackageManagerService.java"
},
"signature_version": "v1"
}
],
"types": [
"EoP"
],
"spl": "2024-03-01",
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/fbdeb248db7dee192392d82fe15482760b8af941"
],
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"296482673243063769976797443477832218939",
"205080326645713381622697273196627504899",
"24191776365121312118246009668773113657",
"328687726879581702857568231538760663042"
]
},
"id": "ASB-A-299441833-1f7b20f3",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/base/+/c61ee9f45233a35da687942d5af24a5d09568a6c",
"deprecated": false,
"target": {
"file": "services/core/java/com/android/server/pm/InstallPackageHelper.java"
},
"signature_version": "v1"
},
{
"digest": {
"function_hash": "280918193978644490386676326143105001422",
"length": 3355.0
},
"id": "ASB-A-299441833-62b8e079",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/base/+/c61ee9f45233a35da687942d5af24a5d09568a6c",
"deprecated": false,
"target": {
"function": "installExistingPackageAsUser",
"file": "services/core/java/com/android/server/pm/InstallPackageHelper.java"
},
"signature_version": "v1"
}
],
"types": [
"EoP"
],
"spl": "2024-03-01",
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/c61ee9f45233a35da687942d5af24a5d09568a6c"
],
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"function_hash": "138592199527733483268954287749153569731",
"length": 3762.0
},
"id": "ASB-A-299441833-d5f02267",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/base/+/b978fdc30bf3dc8babb60ce88be47cf5b0622e84",
"deprecated": false,
"target": {
"function": "installExistingPackageAsUser",
"file": "services/core/java/com/android/server/pm/InstallPackageHelper.java"
},
"signature_version": "v1"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"223414134673961314150758707332884666599",
"297832111914664628625290241149198251561",
"200773103184735589871286713125911464428",
"328687726879581702857568231538760663042"
]
},
"id": "ASB-A-299441833-e1da6e56",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/base/+/b978fdc30bf3dc8babb60ce88be47cf5b0622e84",
"deprecated": false,
"target": {
"file": "services/core/java/com/android/server/pm/InstallPackageHelper.java"
},
"signature_version": "v1"
}
],
"types": [
"EoP"
],
"spl": "2024-03-01",
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/b978fdc30bf3dc8babb60ce88be47cf5b0622e84"
],
"severity": "High"
}