In UnwindingWorker of unwinding.cc, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "match_only_versions": [ "13" ], "digest": { "threshold": 0.9, "line_hashes": [ "88545782820470722185258939600760124082", "141185074383073179309257259460373829530", "151911977581720218950056226347624371621", "291385474918072065364481440096143627881", "4319774242246258842648944880925668600", "109791571089080802379767279196878690069" ] }, "id": "PUB-A-233338564-560fbc0a", "source": "https://android.googlesource.com/platform/external/perfetto/+/7076286ad6373cdc79b989652929236f8e9841ef", "deprecated": false, "signature_version": "v1", "target": { "file": "src/profiling/memory/unwinding.h" }, "signature_type": "Line" }, { "match_only_versions": [ "13" ], "digest": { "threshold": 0.9, "line_hashes": [ "278109555857641491656739200814794431822", "180342086707531848116863261382111200309", "320889837013034100650056372438105173383" ] }, "id": "PUB-A-233338564-7e2cd29c", "source": "https://android.googlesource.com/platform/external/perfetto/+/7076286ad6373cdc79b989652929236f8e9841ef", "deprecated": false, "signature_version": "v1", "target": { "file": "src/profiling/memory/unwinding.cc" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/external/perfetto/+/7076286ad6373cdc79b989652929236f8e9841ef" ], "spl": "2023-03-01", "severity": "Moderate", "types": [ "EoP" ] }