ASB-A-329701910

See a problem?
Import Source
https://storage.googleapis.com/android-osv/ASB-A-329701910.json
JSON Data
https://api.osv.dev/v1/vulns/ASB-A-329701910
Aliases
Published
2024-11-01T00:00:00Z
Modified
2024-11-06T16:12:06.972310Z
Summary
[none]
Details

In multiple locations of legacy.rs, there is a possible bypass of device protection on the Attestation ID due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

References

Affected packages

Android / platform/system/keymint

Affected ranges

Type
ECOSYSTEM
Events
Introduced
15-next:0
Fixed
15-next:2024-11-01

Affected versions

Other

15-next

Ecosystem specific

{
    "fixes": [
        "https://android.googlesource.com/platform/system/keymint/+/6b764647e769c8b1bf3bb131ecc6724f4fee7a82"
    ],
    "spl": "2024-11-01",
    "severity": "High",
    "types": [
        "EoP"
    ]
}