In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "fixes": [ "https://android.googlesource.com/platform/frameworks/av/+/53298956ba6bb8f147a632d7aaed8566dfc203ee" ], "vanir_signatures": [ { "id": "ASB-A-329641908-93b85f5b", "signature_type": "Function", "deprecated": false, "digest": { "length": 1836.0, "function_hash": "270907061862744315091167887695626519942" }, "target": { "file": "media/libstagefright/omx/SoftVideoDecoderOMXComponent.cpp", "function": "SoftVideoDecoderOMXComponent::getConfig" }, "signature_version": "v1", "source": "https://android.googlesource.com/platform/frameworks/av/+/53298956ba6bb8f147a632d7aaed8566dfc203ee" }, { "id": "ASB-A-329641908-ee438024", "signature_type": "Line", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "323840415345152352608431062819861833872", "291742421858830832420113385530445475501", "220311751295838541376304184315980191218", "285456336744440996357481798234586458990" ] }, "target": { "file": "media/libstagefright/omx/SoftVideoDecoderOMXComponent.cpp" }, "signature_version": "v1", "source": "https://android.googlesource.com/platform/frameworks/av/+/53298956ba6bb8f147a632d7aaed8566dfc203ee" } ], "severity": "High", "types": [ "EoP" ], "spl": "2024-09-01" }
{ "fixes": [ "https://android.googlesource.com/platform/frameworks/av/+/f816148a719d2a3bbf432f11da98b3d5fa7de74f" ], "vanir_signatures": [ { "id": "ASB-A-329641908-607c3ede", "signature_type": "Function", "deprecated": false, "digest": { "length": 1836.0, "function_hash": "270907061862744315091167887695626519942" }, "target": { "file": "media/libstagefright/omx/SoftVideoDecoderOMXComponent.cpp", "function": "SoftVideoDecoderOMXComponent::getConfig" }, "signature_version": "v1", "source": "https://android.googlesource.com/platform/frameworks/av/+/f816148a719d2a3bbf432f11da98b3d5fa7de74f" }, { "id": "ASB-A-329641908-6c9ead8c", "signature_type": "Line", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "323840415345152352608431062819861833872", "291742421858830832420113385530445475501", "220311751295838541376304184315980191218", "285456336744440996357481798234586458990" ] }, "target": { "file": "media/libstagefright/omx/SoftVideoDecoderOMXComponent.cpp" }, "signature_version": "v1", "source": "https://android.googlesource.com/platform/frameworks/av/+/f816148a719d2a3bbf432f11da98b3d5fa7de74f" } ], "severity": "High", "types": [ "EoP" ], "spl": "2024-09-01" }
{ "fixes": [ "https://android.googlesource.com/platform/frameworks/av/+/f816148a719d2a3bbf432f11da98b3d5fa7de74f" ], "vanir_signatures": [ { "id": "ASB-A-329641908-4745dab8", "signature_type": "Line", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "323840415345152352608431062819861833872", "291742421858830832420113385530445475501", "220311751295838541376304184315980191218", "285456336744440996357481798234586458990" ] }, "target": { "file": "media/libstagefright/omx/SoftVideoDecoderOMXComponent.cpp" }, "signature_version": "v1", "source": "https://android.googlesource.com/platform/frameworks/av/+/f816148a719d2a3bbf432f11da98b3d5fa7de74f" }, { "id": "ASB-A-329641908-bd61418f", "signature_type": "Function", "deprecated": false, "digest": { "length": 1836.0, "function_hash": "270907061862744315091167887695626519942" }, "target": { "file": "media/libstagefright/omx/SoftVideoDecoderOMXComponent.cpp", "function": "SoftVideoDecoderOMXComponent::getConfig" }, "signature_version": "v1", "source": "https://android.googlesource.com/platform/frameworks/av/+/f816148a719d2a3bbf432f11da98b3d5fa7de74f" } ], "severity": "High", "types": [ "EoP" ], "spl": "2024-09-01" }
{ "fixes": [ "https://android.googlesource.com/platform/frameworks/av/+/f816148a719d2a3bbf432f11da98b3d5fa7de74f" ], "vanir_signatures": [ { "id": "ASB-A-329641908-2c58ae46", "signature_type": "Function", "deprecated": false, "digest": { "length": 1836.0, "function_hash": "270907061862744315091167887695626519942" }, "target": { "file": "media/libstagefright/omx/SoftVideoDecoderOMXComponent.cpp", "function": "SoftVideoDecoderOMXComponent::getConfig" }, "signature_version": "v1", "source": "https://android.googlesource.com/platform/frameworks/av/+/f816148a719d2a3bbf432f11da98b3d5fa7de74f" }, { "id": "ASB-A-329641908-822c0d49", "signature_type": "Line", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "323840415345152352608431062819861833872", "291742421858830832420113385530445475501", "220311751295838541376304184315980191218", "285456336744440996357481798234586458990" ] }, "target": { "file": "media/libstagefright/omx/SoftVideoDecoderOMXComponent.cpp" }, "signature_version": "v1", "source": "https://android.googlesource.com/platform/frameworks/av/+/f816148a719d2a3bbf432f11da98b3d5fa7de74f" } ], "severity": "High", "types": [ "EoP" ], "spl": "2024-09-01" }
{ "fixes": [ "https://android.googlesource.com/platform/frameworks/av/+/f816148a719d2a3bbf432f11da98b3d5fa7de74f" ], "vanir_signatures": [ { "id": "ASB-A-329641908-1eb1c569", "signature_type": "Line", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "323840415345152352608431062819861833872", "291742421858830832420113385530445475501", "220311751295838541376304184315980191218", "285456336744440996357481798234586458990" ] }, "target": { "file": "media/libstagefright/omx/SoftVideoDecoderOMXComponent.cpp" }, "signature_version": "v1", "source": "https://android.googlesource.com/platform/frameworks/av/+/f816148a719d2a3bbf432f11da98b3d5fa7de74f" }, { "id": "ASB-A-329641908-b328fbb4", "signature_type": "Function", "deprecated": false, "digest": { "length": 1836.0, "function_hash": "270907061862744315091167887695626519942" }, "target": { "file": "media/libstagefright/omx/SoftVideoDecoderOMXComponent.cpp", "function": "SoftVideoDecoderOMXComponent::getConfig" }, "signature_version": "v1", "source": "https://android.googlesource.com/platform/frameworks/av/+/f816148a719d2a3bbf432f11da98b3d5fa7de74f" } ], "severity": "High", "types": [ "EoP" ], "spl": "2024-09-01" }