In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "length": 1221.0, "function_hash": "78732347906451052210981180607239984425" }, "id": "ASB-A-344620577-76438a24", "source": "https://android.googlesource.com/platform/external/skia/+/0b628a960e74197ace9831ef0727f5ba7ab6ac10", "deprecated": false, "signature_version": "v1", "target": { "file": "src/effects/SkEmbossMaskFilter.cpp", "function": "SkEmbossMaskFilter::filterMask" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "14494157935654513123308854464673911178", "279325823399751052267469359811888250878", "228380023518619776170140081687866249952", "29867092873288618937979868586134351355", "187021280865865157676648648159678703114", "71096585475333243374566264465524252053", "210406745084159479596954240817223713018", "328622235589218379446054112867661556427" ] }, "id": "ASB-A-344620577-e8688391", "source": "https://android.googlesource.com/platform/external/skia/+/0b628a960e74197ace9831ef0727f5ba7ab6ac10", "deprecated": false, "signature_version": "v1", "target": { "file": "src/effects/SkEmbossMaskFilter.cpp" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/external/skia/+/0b628a960e74197ace9831ef0727f5ba7ab6ac10" ], "spl": "2024-11-01", "severity": "High", "types": [ "RCE" ] }
{ "vanir_signatures": [ { "digest": { "length": 1221.0, "function_hash": "78732347906451052210981180607239984425" }, "id": "ASB-A-344620577-2d6e65b6", "source": "https://android.googlesource.com/platform/external/skia/+/0b628a960e74197ace9831ef0727f5ba7ab6ac10", "deprecated": false, "signature_version": "v1", "target": { "file": "src/effects/SkEmbossMaskFilter.cpp", "function": "SkEmbossMaskFilter::filterMask" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "14494157935654513123308854464673911178", "279325823399751052267469359811888250878", "228380023518619776170140081687866249952", "29867092873288618937979868586134351355", "187021280865865157676648648159678703114", "71096585475333243374566264465524252053", "210406745084159479596954240817223713018", "328622235589218379446054112867661556427" ] }, "id": "ASB-A-344620577-9d186eb1", "source": "https://android.googlesource.com/platform/external/skia/+/0b628a960e74197ace9831ef0727f5ba7ab6ac10", "deprecated": false, "signature_version": "v1", "target": { "file": "src/effects/SkEmbossMaskFilter.cpp" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/external/skia/+/0b628a960e74197ace9831ef0727f5ba7ab6ac10" ], "spl": "2024-11-01", "severity": "High", "types": [ "RCE" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "14494157935654513123308854464673911178", "279325823399751052267469359811888250878", "228380023518619776170140081687866249952", "29867092873288618937979868586134351355", "187021280865865157676648648159678703114", "71096585475333243374566264465524252053", "210406745084159479596954240817223713018", "328622235589218379446054112867661556427" ] }, "id": "ASB-A-344620577-076ccf33", "source": "https://android.googlesource.com/platform/external/skia/+/0b628a960e74197ace9831ef0727f5ba7ab6ac10", "deprecated": false, "signature_version": "v1", "target": { "file": "src/effects/SkEmbossMaskFilter.cpp" }, "signature_type": "Line" }, { "digest": { "length": 1221.0, "function_hash": "78732347906451052210981180607239984425" }, "id": "ASB-A-344620577-bd1cb909", "source": "https://android.googlesource.com/platform/external/skia/+/0b628a960e74197ace9831ef0727f5ba7ab6ac10", "deprecated": false, "signature_version": "v1", "target": { "file": "src/effects/SkEmbossMaskFilter.cpp", "function": "SkEmbossMaskFilter::filterMask" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/external/skia/+/0b628a960e74197ace9831ef0727f5ba7ab6ac10" ], "spl": "2024-11-01", "severity": "High", "types": [ "RCE" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "14494157935654513123308854464673911178", "279325823399751052267469359811888250878", "228380023518619776170140081687866249952", "29867092873288618937979868586134351355", "187021280865865157676648648159678703114", "71096585475333243374566264465524252053", "210406745084159479596954240817223713018", "328622235589218379446054112867661556427" ] }, "id": "ASB-A-344620577-a89cbd07", "source": "https://android.googlesource.com/platform/external/skia/+/0b628a960e74197ace9831ef0727f5ba7ab6ac10", "deprecated": false, "signature_version": "v1", "target": { "file": "src/effects/SkEmbossMaskFilter.cpp" }, "signature_type": "Line" }, { "digest": { "length": 1221.0, "function_hash": "78732347906451052210981180607239984425" }, "id": "ASB-A-344620577-ca5fdd62", "source": "https://android.googlesource.com/platform/external/skia/+/0b628a960e74197ace9831ef0727f5ba7ab6ac10", "deprecated": false, "signature_version": "v1", "target": { "file": "src/effects/SkEmbossMaskFilter.cpp", "function": "SkEmbossMaskFilter::filterMask" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/external/skia/+/0b628a960e74197ace9831ef0727f5ba7ab6ac10" ], "spl": "2024-11-01", "severity": "High", "types": [ "RCE" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "14494157935654513123308854464673911178", "279325823399751052267469359811888250878", "228380023518619776170140081687866249952", "29867092873288618937979868586134351355", "187021280865865157676648648159678703114", "71096585475333243374566264465524252053", "210406745084159479596954240817223713018", "328622235589218379446054112867661556427" ] }, "id": "ASB-A-344620577-8f0b7188", "source": "https://android.googlesource.com/platform/external/skia/+/0b628a960e74197ace9831ef0727f5ba7ab6ac10", "deprecated": false, "signature_version": "v1", "target": { "file": "src/effects/SkEmbossMaskFilter.cpp" }, "signature_type": "Line" }, { "digest": { "length": 1221.0, "function_hash": "78732347906451052210981180607239984425" }, "id": "ASB-A-344620577-ed5e6808", "source": "https://android.googlesource.com/platform/external/skia/+/0b628a960e74197ace9831ef0727f5ba7ab6ac10", "deprecated": false, "signature_version": "v1", "target": { "file": "src/effects/SkEmbossMaskFilter.cpp", "function": "SkEmbossMaskFilter::filterMask" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/external/skia/+/0b628a960e74197ace9831ef0727f5ba7ab6ac10" ], "spl": "2024-11-01", "severity": "High", "types": [ "RCE" ] }