In legacyparseparam of fs_context.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
{
"types": [
"EoP"
],
"spl": "2022-06-05",
"severity": "Moderate",
"vanir_signatures": [
{
"id": "PUB-A-213172369-44cea301",
"source": "https://android.googlesource.com/kernel/common/+/a32e89883a535",
"signature_version": "v1",
"digest": {
"line_hashes": [
"332611879140404434690152632347982780701",
"193005555054335394959908412522152239921",
"308843018842959193664841224512432202885",
"251322244919373171567936309461685841974"
],
"threshold": 0.9
},
"deprecated": false,
"signature_type": "Line",
"target": {
"file": "fs/fs_context.c"
}
},
{
"id": "PUB-A-213172369-4d2f18b1",
"source": "https://android.googlesource.com/kernel/common/+/a32e89883a535",
"signature_version": "v1",
"digest": {
"length": 1796.0,
"function_hash": "67543043462929298139978757926468672210"
},
"deprecated": false,
"signature_type": "Function",
"target": {
"function": "legacy_parse_param",
"file": "fs/fs_context.c"
}
},
{
"id": "PUB-A-213172369-a492c0a0",
"source": "https://android.googlesource.com/kernel/common/+/eadde287a62e6",
"signature_version": "v1",
"digest": {
"line_hashes": [
"332611879140404434690152632347982780701",
"193005555054335394959908412522152239921",
"308843018842959193664841224512432202885",
"251322244919373171567936309461685841974"
],
"threshold": 0.9
},
"deprecated": false,
"signature_type": "Line",
"target": {
"file": "fs/fs_context.c"
}
},
{
"id": "PUB-A-213172369-aad49fbf",
"source": "https://android.googlesource.com/kernel/common/+/eadde287a62e6",
"signature_version": "v1",
"digest": {
"length": 1796.0,
"function_hash": "67543043462929298139978757926468672210"
},
"deprecated": false,
"signature_type": "Function",
"target": {
"function": "legacy_parse_param",
"file": "fs/fs_context.c"
}
}
],
"fixes": [
"https://android.googlesource.com/kernel/common/+/a32e89883a535",
"https://android.googlesource.com/kernel/common/+/eadde287a62e6"
]
}