In (TBD) of (TBD), there is a possible out of bounds write due to kernel stack overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
{
"spl": "2022-08-05",
"vanir_signatures": [
{
"target": {
"file": "fs/incfs/vfs.c",
"function": "incfs_kill_sb"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"id": "PUB-A-214245176-1181db2a",
"digest": {
"function_hash": "176670731325477146299934636839845780978",
"length": 145.0
},
"source": "https://android.googlesource.com/kernel/common/+/f545f0a2a0b851359ef25fc2f21a978393c5efbb"
},
{
"target": {
"file": "fs/incfs/data_mgmt.h"
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"id": "PUB-A-214245176-220ebd41",
"digest": {
"line_hashes": [
"330086807963617695372970505453970515723",
"239760600571694219025838336052510279047",
"46679404005639728795228354140203729700",
"111980593714080674767836741614064364045",
"333779393098295415669831954338703877244"
],
"threshold": 0.9
},
"source": "https://android.googlesource.com/kernel/common/+/f545f0a2a0b851359ef25fc2f21a978393c5efbb"
},
{
"target": {
"file": "fs/incfs/vfs.c",
"function": "open_or_create_special_dir"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"id": "PUB-A-214245176-71ef9ebb",
"digest": {
"function_hash": "274986948291723849792271119599204060626",
"length": 603.0
},
"source": "https://android.googlesource.com/kernel/common/+/f545f0a2a0b851359ef25fc2f21a978393c5efbb"
},
{
"target": {
"file": "fs/incfs/vfs.c"
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"id": "PUB-A-214245176-bf8e5074",
"digest": {
"line_hashes": [
"255046638516086091558336750443031813849",
"5291619991875032880586457423242800763",
"101881557961430715435257807725024265422",
"332818963944019690452939433220691215501",
"278109889219699472424843297462750218574",
"251102517926587213380233421952849591650",
"151026451549093755682919576385246327887",
"91355420355464314706544193951094422832",
"308002087569889509357126574590684444047",
"168757702176028916384666502653353965487",
"185179338232784229094901898637252131853",
"61573193585702103680484660484189935689",
"260690500772016033591300501730403663272",
"328473044242411098187962781763041342103",
"65873696291473240328343595739052005200",
"75594632753307245227786936294711324975",
"36950445903869328206362156208083921325",
"49071205218719449384784528715707881818",
"122715722328560756710145034010652850053",
"160963192354156839602766648867822705710",
"64993335526613733633136636942958972444",
"12911008854375869358512508136236841012",
"235828491724184238612569409095325477807",
"68981397340655087138716739319450109908",
"58027371395789013537288402076158104952",
"30310582014466436457952642296600778125",
"70420551373903119378459703111925866660",
"102666365565533951628228158070162872092",
"186340601974642922168013525003310853383",
"337730500418017423582046622046324441721",
"131959375518692655511015564729789967400",
"55058310661535386030172555773869390356",
"19748788029726962710278349152910655501",
"295855826707249981007249655178277929741",
"59996525602984760067589832232488333239",
"98813091912606471889117382249404377179",
"315947109254738752601346322356852902074",
"60826268010596968893691815310733802848",
"5890929299870111538127285039892909661",
"332517929998353964179406258173658818023",
"193522467073190475982812483308440209252",
"26471783844442395268271198659033695467",
"163133554022094815039159340698049462650",
"176707628827111726522492745730823760844",
"22870392661893165149064405161829869556",
"153920470626841045398779580071093597634",
"43598670952284691762821763183127659989",
"176821408175756020988372829919981647941",
"147631160965459401683913194160829404785",
"104789137035102897271827861748121440213",
"10649115594233507910965454425646957475",
"246747512800517687644992180131759582950",
"190311274058559807260437926212594233632",
"304735231182058664597609708464506565595",
"212952816198012000109700856999934324773",
"44225105940481537276454835058824223777",
"84589193417334342861225952721460122373",
"287842845871564660964736274662078936621",
"120775583859263939775802676632456039709",
"117477971171136691980788010265350493922",
"99949461872511051145156325765967812858",
"226910515563183613268453327994921185949",
"162304169024702078901315428552500489827",
"99861502394263066583251556393103430078",
"66391143225462062945939040745202783741",
"188946167843599334071139513038029478038",
"250099953786627029861220089367506493480",
"283157270435922667775138862133408759016",
"193410632596557428035565641359535963683",
"109641466878201899800048161089267067982",
"271351888715597680428401244869487694550",
"281108998110984429089298994459839414718",
"336649036807126579558674777194872698790",
"92400285832190523171942616840323464456",
"153815980114737523267745292376071485085",
"236416441865560244048239372904876766346",
"297508226308374666786365465036090585549",
"92566205946529405430525009652448782985",
"77025181939465380062562314007564265977",
"81510759406937582951954366506582629613",
"63376032324002090940401283593855738941",
"272808589125285184641139513674449629622",
"109671829295588493871582850386728759665",
"287620402263006068824595768174504987333",
"292142291150969372464238092594041436297",
"120649543602550004721897117708439964382",
"223725388585519233368485543069791306146",
"253722257311859832631593913903966040780",
"106322683106594431227325560534592806722",
"225420716378333655073572306058152307553"
],
"threshold": 0.9
},
"source": "https://android.googlesource.com/kernel/common/+/f545f0a2a0b851359ef25fc2f21a978393c5efbb"
},
{
"target": {
"file": "fs/incfs/vfs.c",
"function": "incfs_mount_fs"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"id": "PUB-A-214245176-c69cc866",
"digest": {
"function_hash": "178306915234749092184925781403649852606",
"length": 2692.0
},
"source": "https://android.googlesource.com/kernel/common/+/f545f0a2a0b851359ef25fc2f21a978393c5efbb"
}
],
"severity": "Moderate",
"fixes": [
"https://android.googlesource.com/kernel/common/+/f545f0a2a0b851359ef25fc2f21a978393c5efbb"
],
"types": [
"EoP"
]
}