In memzero_explicit of compiler-clang.h, there is a possible bypass of defense in depth due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"types": [
"ID"
],
"fixes": [
"https://android.googlesource.com/kernel/common/+/b207caff4176"
],
"spl": "2021-10-05",
"vanir_signatures": [
{
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/kernel/common/+/b207caff4176",
"id": "PUB-A-171418586-d5f38565",
"digest": {
"line_hashes": [
"155912257525755603248824695362303775945",
"332555238510405985194080792431790876117",
"145223449976152462925900263703735570961",
"189588853937692635912054551593829697886",
"171476834957445749975955936806750340909",
"322830413972318245308229436526543128295",
"101517464112037253994975915085192448931"
],
"threshold": 0.9
},
"signature_type": "Line",
"target": {
"file": "include/linux/compiler.h"
}
}
],
"severity": "Moderate"
}