In memzero_explicit of compiler-clang.h, there is a possible bypass of defense in depth due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "155912257525755603248824695362303775945", "332555238510405985194080792431790876117", "145223449976152462925900263703735570961", "189588853937692635912054551593829697886", "171476834957445749975955936806750340909", "322830413972318245308229436526543128295", "101517464112037253994975915085192448931" ] }, "id": "PUB-A-171418586-d5f38565", "source": "http://android.googlesource.com/kernel/common/+/b207caff4176", "deprecated": false, "signature_version": "v1", "target": { "file": "include/linux/compiler.h" }, "signature_type": "Line" } ], "fixes": [ "http://android.googlesource.com/kernel/common/+/b207caff4176" ], "spl": "2021-10-05", "severity": "Moderate", "types": [ "ID" ] }