In loadLabel of PackageItemInfo.java, there is a possible way to DoS a device by having a long label in an app due to incorrect input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
{
"types": [
"DoS"
],
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/b02bae5d5acedd5d7c6f0a8f15a371ad73f6c630",
"digest": {
"length": 291.0,
"function_hash": "197262744676345747451146645210352402389"
},
"id": "ASB-A-67013844-20351e3e",
"target": {
"function": "loadLabel",
"file": "core/java/android/content/pm/PackageItemInfo.java"
},
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1"
},
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/b02bae5d5acedd5d7c6f0a8f15a371ad73f6c630",
"id": "ASB-A-67013844-f29da8c0",
"digest": {
"line_hashes": [
"203471766889988222920160561012837580289",
"211598420933719432426440751445071299781",
"103974876474381423283561351254285338338",
"87326961549657539380601366314994863791"
],
"threshold": 0.9
},
"target": {
"file": "core/java/android/content/pm/PackageItemInfo.java"
},
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1"
}
],
"severity": "High",
"spl": "2021-10-01",
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/b02bae5d5acedd5d7c6f0a8f15a371ad73f6c630"
]
}{
"types": [
"DoS"
],
"spl": "2021-10-01",
"severity": "High",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/b55d314f4685fb459307deff88ddfc704ecc4faa",
"digest": {
"line_hashes": [
"110016614989350130356397460719479309930",
"203780712523424795160855180034997561928",
"92947797229938919218638437430263796409",
"116274070298875288416326727720725418863",
"279728423330176809054242768736329296087",
"7125180016472757302835857405453831766",
"103974876474381423283561351254285338338",
"87326961549657539380601366314994863791"
],
"threshold": 0.9
},
"id": "ASB-A-67013844-2cfbc44c",
"deprecated": false,
"target": {
"file": "core/java/android/content/pm/PackageItemInfo.java"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/b55d314f4685fb459307deff88ddfc704ecc4faa",
"digest": {
"length": 137.0,
"function_hash": "137756697787926226631439036334541948224"
},
"id": "ASB-A-67013844-e66fabb8",
"target": {
"function": "loadLabel",
"file": "core/java/android/content/pm/PackageItemInfo.java"
},
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1"
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/b55d314f4685fb459307deff88ddfc704ecc4faa"
]
}{
"types": [
"DoS"
],
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/61722016377e992b5e2e63d5886684f8ac195c7e",
"digest": {
"length": 219.0,
"function_hash": "332939461709339361146363198267133723516"
},
"id": "ASB-A-67013844-308fa358",
"target": {
"function": "loadLabel",
"file": "core/java/android/content/pm/PackageItemInfo.java"
},
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1"
},
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/61722016377e992b5e2e63d5886684f8ac195c7e",
"digest": {
"line_hashes": [
"211729449204383603725758113709580431487",
"16461481583911868172517903881119322936",
"59502862439743143454233260649232848988",
"49066076344207302682434259207841754298",
"203471766889988222920160561012837580289",
"211598420933719432426440751445071299781",
"103974876474381423283561351254285338338",
"87326961549657539380601366314994863791"
],
"threshold": 0.9
},
"id": "ASB-A-67013844-f6cc1d1c",
"target": {
"file": "core/java/android/content/pm/PackageItemInfo.java"
},
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1"
}
],
"severity": "High",
"spl": "2021-10-01",
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/61722016377e992b5e2e63d5886684f8ac195c7e"
]
}{
"types": [
"DoS"
],
"spl": "2021-10-01",
"severity": "High",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/3c26a24644feaf2860892809929dec816f354bae",
"digest": {
"line_hashes": [
"203471766889988222920160561012837580289",
"211598420933719432426440751445071299781",
"103974876474381423283561351254285338338",
"87326961549657539380601366314994863791"
],
"threshold": 0.9
},
"id": "ASB-A-67013844-2432d328",
"target": {
"file": "core/java/android/content/pm/PackageItemInfo.java"
},
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1"
},
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/3c26a24644feaf2860892809929dec816f354bae",
"digest": {
"length": 291.0,
"function_hash": "197262744676345747451146645210352402389"
},
"id": "ASB-A-67013844-2df1169e",
"target": {
"function": "loadLabel",
"file": "core/java/android/content/pm/PackageItemInfo.java"
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function"
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/3c26a24644feaf2860892809929dec816f354bae"
]
}{
"types": [
"DoS"
],
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/cd8558a2533d08107e761596686c2b24839b3e36",
"digest": {
"line_hashes": [
"203471766889988222920160561012837580289",
"211598420933719432426440751445071299781",
"103974876474381423283561351254285338338",
"87326961549657539380601366314994863791"
],
"threshold": 0.9
},
"id": "ASB-A-67013844-baddbfd3",
"deprecated": false,
"target": {
"file": "core/java/android/content/pm/PackageItemInfo.java"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/cd8558a2533d08107e761596686c2b24839b3e36",
"digest": {
"length": 291.0,
"function_hash": "197262744676345747451146645210352402389"
},
"id": "ASB-A-67013844-f6abd6b6",
"target": {
"function": "loadLabel",
"file": "core/java/android/content/pm/PackageItemInfo.java"
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function"
}
],
"severity": "High",
"spl": "2021-10-01",
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/cd8558a2533d08107e761596686c2b24839b3e36"
]
}