ASB-A-316893159

See a problem?
Import Source
https://storage.googleapis.com/android-osv/ASB-A-316893159.json
JSON Data
https://api.osv.dev/v1/vulns/ASB-A-316893159
Aliases
Published
2024-03-01T00:00:00Z
Modified
2026-04-24T15:37:38.793646Z
Summary
[none]
Details

In Session of AccountManagerService.java, there is a possible method to retain foreground service privileges due to incorrect handling of null responses. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

References

Affected packages

Android
platform/frameworks/base

Package

Name
platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14-next:0
Fixed
14-next:2024-03-01

Affected versions

Other
14-next

Ecosystem specific

{
    "vanir_signatures": [
        {
            "digest": {
                "function_hash": "265328424312928374515768229782878598753",
                "length": 680.0
            },
            "id": "ASB-A-316893159-93b0c788",
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/c1b2d61dd84467ba2621a17718761ad4949dfd5e",
            "deprecated": false,
            "target": {
                "function": "Session",
                "file": "services/core/java/com/android/server/accounts/AccountManagerService.java"
            },
            "signature_version": "v1"
        },
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "147516298131624241384756167266658125938",
                    "39791194325251257456986993978544102798",
                    "27254244033986831096454444969228777862",
                    "73114813082680463078622503072237150951",
                    "265907424551711755248114247518782074159",
                    "20933846279482472287914415765660668423",
                    "126153835675113937042994305411507819078",
                    "318018205287503207077538754512504815299",
                    "242451460847616123178063495162102141122",
                    "84373260278207685014432832870756667011",
                    "130619544422725740809277217888075915016",
                    "106189489982922899031012766179206677335",
                    "14255875241294422934386317586187022806",
                    "205782882345301555749511224884459230186"
                ]
            },
            "id": "ASB-A-316893159-bc402f95",
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/c1b2d61dd84467ba2621a17718761ad4949dfd5e",
            "deprecated": false,
            "target": {
                "file": "services/core/java/com/android/server/accounts/AccountManagerService.java"
            },
            "signature_version": "v1"
        },
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "134633262403625574119509815301232138664",
                    "56314270232463790916276195357229955021",
                    "128325795429514723275558386072991325974",
                    "285865900335380423290357690358398924324"
                ]
            },
            "id": "ASB-A-316893159-bc450520",
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/89af0a39c23abf0464a96e5ba7eec332b675a69e",
            "deprecated": false,
            "target": {
                "file": "services/core/java/com/android/server/accounts/AccountManagerService.java"
            },
            "signature_version": "v1"
        },
        {
            "digest": {
                "function_hash": "133645332067243858162289430740295177188",
                "length": 333.0
            },
            "id": "ASB-A-316893159-ed570c09",
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/c1b2d61dd84467ba2621a17718761ad4949dfd5e",
            "deprecated": false,
            "target": {
                "function": "onTimedOut",
                "file": "services/core/java/com/android/server/accounts/AccountManagerService.java"
            },
            "signature_version": "v1"
        }
    ],
    "types": [
        "EoP"
    ],
    "spl": "2024-03-01",
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/c1b2d61dd84467ba2621a17718761ad4949dfd5e",
        "https://android.googlesource.com/platform/frameworks/base/+/89af0a39c23abf0464a96e5ba7eec332b675a69e"
    ],
    "severity": "High"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-316893159.json"
platform/frameworks/base

Package

Name
platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
12:0
Fixed
12:2024-03-01

Affected versions

Other
12

Ecosystem specific

{
    "vanir_signatures": [
        {
            "digest": {
                "function_hash": "154113943960998969999173728755529315304",
                "length": 699.0
            },
            "id": "ASB-A-316893159-4968643c",
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/bb53f192e0ceaa026a083da156ef0cb0140f0c09",
            "deprecated": false,
            "target": {
                "function": "Session",
                "file": "services/core/java/com/android/server/accounts/AccountManagerService.java"
            },
            "signature_version": "v1"
        },
        {
            "digest": {
                "function_hash": "133645332067243858162289430740295177188",
                "length": 333.0
            },
            "id": "ASB-A-316893159-f1333e00",
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/bb53f192e0ceaa026a083da156ef0cb0140f0c09",
            "deprecated": false,
            "target": {
                "function": "onTimedOut",
                "file": "services/core/java/com/android/server/accounts/AccountManagerService.java"
            },
            "signature_version": "v1"
        },
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "147516298131624241384756167266658125938",
                    "39791194325251257456986993978544102798",
                    "27254244033986831096454444969228777862",
                    "73114813082680463078622503072237150951",
                    "265907424551711755248114247518782074159",
                    "20933846279482472287914415765660668423",
                    "126153835675113937042994305411507819078",
                    "84602381484422346330323891832756860196",
                    "242451460847616123178063495162102141122",
                    "84373260278207685014432832870756667011",
                    "130619544422725740809277217888075915016",
                    "106189489982922899031012766179206677335",
                    "14255875241294422934386317586187022806",
                    "205782882345301555749511224884459230186"
                ]
            },
            "id": "ASB-A-316893159-ff47a9a4",
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/bb53f192e0ceaa026a083da156ef0cb0140f0c09",
            "deprecated": false,
            "target": {
                "file": "services/core/java/com/android/server/accounts/AccountManagerService.java"
            },
            "signature_version": "v1"
        }
    ],
    "types": [
        "EoP"
    ],
    "spl": "2024-03-01",
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/bb53f192e0ceaa026a083da156ef0cb0140f0c09"
    ],
    "severity": "High"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-316893159.json"
platform/frameworks/base

Package

Name
platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
12L:0
Fixed
12L:2024-03-01

Affected versions

Other
12L

Ecosystem specific

{
    "vanir_signatures": [
        {
            "digest": {
                "function_hash": "154113943960998969999173728755529315304",
                "length": 699.0
            },
            "id": "ASB-A-316893159-526cb685",
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/bb53f192e0ceaa026a083da156ef0cb0140f0c09",
            "deprecated": false,
            "target": {
                "function": "Session",
                "file": "services/core/java/com/android/server/accounts/AccountManagerService.java"
            },
            "signature_version": "v1"
        },
        {
            "digest": {
                "function_hash": "133645332067243858162289430740295177188",
                "length": 333.0
            },
            "id": "ASB-A-316893159-a7303bdb",
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/bb53f192e0ceaa026a083da156ef0cb0140f0c09",
            "deprecated": false,
            "target": {
                "function": "onTimedOut",
                "file": "services/core/java/com/android/server/accounts/AccountManagerService.java"
            },
            "signature_version": "v1"
        },
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "147516298131624241384756167266658125938",
                    "39791194325251257456986993978544102798",
                    "27254244033986831096454444969228777862",
                    "73114813082680463078622503072237150951",
                    "265907424551711755248114247518782074159",
                    "20933846279482472287914415765660668423",
                    "126153835675113937042994305411507819078",
                    "84602381484422346330323891832756860196",
                    "242451460847616123178063495162102141122",
                    "84373260278207685014432832870756667011",
                    "130619544422725740809277217888075915016",
                    "106189489982922899031012766179206677335",
                    "14255875241294422934386317586187022806",
                    "205782882345301555749511224884459230186"
                ]
            },
            "id": "ASB-A-316893159-df2b9e7a",
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/bb53f192e0ceaa026a083da156ef0cb0140f0c09",
            "deprecated": false,
            "target": {
                "file": "services/core/java/com/android/server/accounts/AccountManagerService.java"
            },
            "signature_version": "v1"
        }
    ],
    "types": [
        "EoP"
    ],
    "spl": "2024-03-01",
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/bb53f192e0ceaa026a083da156ef0cb0140f0c09"
    ],
    "severity": "High"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-316893159.json"
platform/frameworks/base

Package

Name
platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
13:0
Fixed
13:2024-03-01

Affected versions

Other
13

Ecosystem specific

{
    "vanir_signatures": [
        {
            "digest": {
                "function_hash": "133645332067243858162289430740295177188",
                "length": 333.0
            },
            "id": "ASB-A-316893159-16fb120e",
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/bb53f192e0ceaa026a083da156ef0cb0140f0c09",
            "deprecated": false,
            "target": {
                "function": "onTimedOut",
                "file": "services/core/java/com/android/server/accounts/AccountManagerService.java"
            },
            "signature_version": "v1"
        },
        {
            "digest": {
                "function_hash": "154113943960998969999173728755529315304",
                "length": 699.0
            },
            "id": "ASB-A-316893159-68aa4b1a",
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/bb53f192e0ceaa026a083da156ef0cb0140f0c09",
            "deprecated": false,
            "target": {
                "function": "Session",
                "file": "services/core/java/com/android/server/accounts/AccountManagerService.java"
            },
            "signature_version": "v1"
        },
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "147516298131624241384756167266658125938",
                    "39791194325251257456986993978544102798",
                    "27254244033986831096454444969228777862",
                    "73114813082680463078622503072237150951",
                    "265907424551711755248114247518782074159",
                    "20933846279482472287914415765660668423",
                    "126153835675113937042994305411507819078",
                    "84602381484422346330323891832756860196",
                    "242451460847616123178063495162102141122",
                    "84373260278207685014432832870756667011",
                    "130619544422725740809277217888075915016",
                    "106189489982922899031012766179206677335",
                    "14255875241294422934386317586187022806",
                    "205782882345301555749511224884459230186"
                ]
            },
            "id": "ASB-A-316893159-c292c281",
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/bb53f192e0ceaa026a083da156ef0cb0140f0c09",
            "deprecated": false,
            "target": {
                "file": "services/core/java/com/android/server/accounts/AccountManagerService.java"
            },
            "signature_version": "v1"
        }
    ],
    "types": [
        "EoP"
    ],
    "spl": "2024-03-01",
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/bb53f192e0ceaa026a083da156ef0cb0140f0c09"
    ],
    "severity": "High"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-316893159.json"
platform/frameworks/base

Package

Name
platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14:0
Fixed
14:2024-03-01

Affected versions

Other
14

Ecosystem specific

{
    "vanir_signatures": [
        {
            "digest": {
                "function_hash": "154113943960998969999173728755529315304",
                "length": 699.0
            },
            "id": "ASB-A-316893159-78b2ccf8",
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/bb53f192e0ceaa026a083da156ef0cb0140f0c09",
            "deprecated": false,
            "target": {
                "function": "Session",
                "file": "services/core/java/com/android/server/accounts/AccountManagerService.java"
            },
            "signature_version": "v1"
        },
        {
            "digest": {
                "function_hash": "133645332067243858162289430740295177188",
                "length": 333.0
            },
            "id": "ASB-A-316893159-ee4d74bb",
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/bb53f192e0ceaa026a083da156ef0cb0140f0c09",
            "deprecated": false,
            "target": {
                "function": "onTimedOut",
                "file": "services/core/java/com/android/server/accounts/AccountManagerService.java"
            },
            "signature_version": "v1"
        },
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "147516298131624241384756167266658125938",
                    "39791194325251257456986993978544102798",
                    "27254244033986831096454444969228777862",
                    "73114813082680463078622503072237150951",
                    "265907424551711755248114247518782074159",
                    "20933846279482472287914415765660668423",
                    "126153835675113937042994305411507819078",
                    "84602381484422346330323891832756860196",
                    "242451460847616123178063495162102141122",
                    "84373260278207685014432832870756667011",
                    "130619544422725740809277217888075915016",
                    "106189489982922899031012766179206677335",
                    "14255875241294422934386317586187022806",
                    "205782882345301555749511224884459230186"
                ]
            },
            "id": "ASB-A-316893159-f1cf2842",
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/bb53f192e0ceaa026a083da156ef0cb0140f0c09",
            "deprecated": false,
            "target": {
                "file": "services/core/java/com/android/server/accounts/AccountManagerService.java"
            },
            "signature_version": "v1"
        }
    ],
    "types": [
        "EoP"
    ],
    "spl": "2024-03-01",
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/bb53f192e0ceaa026a083da156ef0cb0140f0c09"
    ],
    "severity": "High"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-316893159.json"