In Exynosparsinguserdataregistereditut_t35 of VendorVideoAPI.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
{
"spl": "2023-06-01",
"fixes": [
"https://android.googlesource.com/platform/hardware/google/gchips/+/75c487c45a40ca66a06722f5ac12b1ece58a6b13"
],
"types": [
"ID"
],
"vanir_signatures": [
{
"match_only_versions": [
"13-next"
],
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"110393419294145333927975244550958528648",
"30779461522252381825653750257199450902",
"163752997980168949483506564070865772387",
"197124901429058004769551657678477006520"
],
"threshold": 0.9
},
"target": {
"file": "include/VendorVideoAPI.h"
},
"id": "PUB-A-252764175-8b63a03b",
"source": "https://android.googlesource.com/platform/hardware/google/gchips/+/75c487c45a40ca66a06722f5ac12b1ece58a6b13",
"signature_version": "v1"
},
{
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"182581172807498517608401806623847762445",
"11734651323018246883399799883219691364",
"266436673382873636585565935850219384440",
"19386917035829971824956363680145203155",
"288003666696654638328961736625138323395",
"85840979306919565775277901674338052279",
"152527333130694181612170269090986399465",
"80790618311609125044124225089649877823",
"270346060247846624672571195924028765095",
"33660464860934763414305455328277954554",
"33946360768637044135657392035522294030",
"61620501149699977937125441982614459110",
"32684410621382859336984223246472034650",
"33946360768637044135657392035522294030",
"13247480742606314829716838518395668137",
"262098992046344821039630075497884059640",
"179864163034560385696888305030676015417",
"145809841884496083078556997948750453326",
"152395261160673331840195020486129164802",
"179864163034560385696888305030676015417",
"325945144054238968896047093285361532052",
"304225207605109204168887291160787572234",
"319501023042922402153059086597335407461",
"159214689713902825530149059629368024251",
"186901356770420397951548660752940876857",
"244313220130784846847259821300365251009",
"31317059182051608271978482473922971815",
"110188320612106258763584006334517208790",
"210713506797445088746877259943475093595",
"112484420503486617211934826343972246552",
"110188320612106258763584006334517208790",
"210713506797445088746877259943475093595",
"112484420503486617211934826343972246552",
"110188320612106258763584006334517208790",
"210713506797445088746877259943475093595",
"112484420503486617211934826343972246552",
"110188320612106258763584006334517208790",
"210713506797445088746877259943475093595",
"112484420503486617211934826343972246552",
"110188320612106258763584006334517208790",
"210713506797445088746877259943475093595",
"112484420503486617211934826343972246552",
"110188320612106258763584006334517208790",
"210713506797445088746877259943475093595",
"330259678526029788509620435184499620251",
"110188320612106258763584006334517208790",
"210713506797445088746877259943475093595",
"112484420503486617211934826343972246552",
"110188320612106258763584006334517208790",
"210713506797445088746877259943475093595",
"112484420503486617211934826343972246552",
"110188320612106258763584006334517208790",
"210713506797445088746877259943475093595",
"112484420503486617211934826343972246552",
"120942857288381002852597434989115660433",
"275493013820668439920356266637882257447",
"219492985612179803867596211322350236243",
"59477089528546236320147109623844776249",
"106460817617930475041626093317668281215",
"125322326058517183634965844799914044909",
"110240825417115269777647375628212457328",
"187583686202245783351211899941031975792",
"7671754239627284804603445693178513826",
"126647991437013121257745274504992121078",
"261514594185540503638660574829702249280",
"152041810455952622627236188051328465373",
"103373564408305994517647250133044901726",
"160812034451585017636066300276746359897",
"198831218778292002441035499901786450816",
"22740232837694339387843830000702153804",
"141607784771605399765196754791404032742",
"50717844565559979798427721093410995763",
"205510126907339749437929707324847666724",
"141012099670024970752573004475745895275",
"320458251671449027703914301236617737252",
"47100071524393611381470928968400398431",
"306294789558957001975715049793198574708",
"95146758386217588282554966661694649619",
"2790904118096634903747996284435429850",
"319313499476516637128688107104994122249",
"239045051439653467931547038148428388931",
"297262468073345917982998286631452146715",
"6959121070700111077951293582189301929",
"297277200207526974590242025121621882512",
"312147725916819792703572107303029950323",
"10285174281797203395588908926924803325",
"146362284262287164678858588001875885560",
"46523761035060979686672839801417850303",
"195397904603323606510188956832964719920",
"151073062314279471555630643694602436338",
"104725654548847444279445766802944262851",
"80993537639332918525421878960789773769",
"8440176370682357733091315649889868951",
"250448007869784050030308439362120104627",
"57876713925441944854557814696809063800",
"252873137281053868206589352714562477442",
"300466616345882195784406469387757501158",
"135405098076047921133490758297403524872",
"154959885755073886255498922414777428733",
"4413272464025526173143633847668838453",
"237144129241424600796003490851335604557",
"18644651554331601872032500268853941861",
"181701674773739700419994106407988956121",
"22740232837694339387843830000702153804",
"140977749603402487362215160172092447236",
"213050748734336018794470702406026544125",
"59109373342793278909991985602419069527",
"90104006538887231453862090675011793267",
"153591530344519563061509772176348860395",
"56050925349642354360165005546180533419",
"130231737081769903503307162845919939260",
"30932856217059918012668191635085404650",
"134063287533457897717814201822041992854",
"304851110619612092425465112514433583268",
"305051545562225504571446997134115785041",
"224313964342440091232689672665833587506",
"132227836804176995926133909691950248538",
"180302646706919952371342405196850873125",
"298051276773135892925158575066269666822",
"201288569560187549111297559967828231368",
"126452061617654159714251472699191698941",
"297277200207526974590242025121621882512",
"24931609180649960367746021185846934000",
"155894473670099304263900294117928435555",
"133512013890906109358866347731190024887",
"92580573049066031862215944186885043372",
"78078928536598151618056313275294089540",
"286445533549120577818045022167036684514",
"203562541634497943637843188231609112545",
"276912660912125857277703369520448481523",
"281384267367864252862755508333228521208",
"196583552427474544808922054667673602272",
"135170623709712571059308874047898000977"
],
"threshold": 0.9
},
"source": "https://android.googlesource.com/platform/hardware/google/gchips/+/75c487c45a40ca66a06722f5ac12b1ece58a6b13",
"target": {
"file": "videoapi/VendorVideoAPI.cpp"
},
"id": "PUB-A-252764175-b1fc28b3"
},
{
"match_only_versions": [
"13-next"
],
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 13830.0,
"function_hash": "123510694490335716381050766905161243346"
},
"target": {
"function": "Exynos_parsing_user_data_registered_itu_t_t35",
"file": "videoapi/VendorVideoAPI.cpp"
},
"id": "PUB-A-252764175-fc28ccda",
"source": "https://android.googlesource.com/platform/hardware/google/gchips/+/75c487c45a40ca66a06722f5ac12b1ece58a6b13",
"signature_version": "v1"
}
],
"severity": "Moderate"
}{
"spl": "2023-06-01",
"fixes": [
"https://android.googlesource.com/platform/hardware/google/graphics/common/+/31ad515db643b6873fed25952b3172aaf8161761"
],
"types": [
"ID"
],
"vanir_signatures": [
{
"match_only_versions": [
"13-next"
],
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"288494675835549734070512860694294321778",
"266720710589569744280202702541864478273",
"50975389984735270905780513613223602051",
"129847710924168018784424963183918388059"
],
"threshold": 0.9
},
"target": {
"file": "libhwc2.1/libdevice/ExynosLayer.cpp"
},
"id": "PUB-A-252764175-43ac3f1b",
"source": "https://android.googlesource.com/platform/hardware/google/graphics/common/+/31ad515db643b6873fed25952b3172aaf8161761",
"signature_version": "v1"
},
{
"match_only_versions": [
"13-next"
],
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 785.0,
"function_hash": "269051373921565162815233825939761381396"
},
"target": {
"function": "ExynosLayer::setLayerPerFrameMetadataBlobs",
"file": "libhwc2.1/libdevice/ExynosLayer.cpp"
},
"id": "PUB-A-252764175-a139834f",
"source": "https://android.googlesource.com/platform/hardware/google/graphics/common/+/31ad515db643b6873fed25952b3172aaf8161761",
"signature_version": "v1"
}
],
"severity": "Moderate"
}{
"spl": "2023-06-01",
"fixes": [
"https://android.googlesource.com/platform/hardware/google/gchips/+/75c487c45a40ca66a06722f5ac12b1ece58a6b13"
],
"types": [
"ID"
],
"vanir_signatures": [
{
"match_only_versions": [
"13"
],
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 13830.0,
"function_hash": "123510694490335716381050766905161243346"
},
"target": {
"function": "Exynos_parsing_user_data_registered_itu_t_t35",
"file": "videoapi/VendorVideoAPI.cpp"
},
"id": "PUB-A-252764175-76e438d4",
"source": "https://android.googlesource.com/platform/hardware/google/gchips/+/75c487c45a40ca66a06722f5ac12b1ece58a6b13",
"signature_version": "v1"
},
{
"match_only_versions": [
"13"
],
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"110393419294145333927975244550958528648",
"30779461522252381825653750257199450902",
"163752997980168949483506564070865772387",
"197124901429058004769551657678477006520"
],
"threshold": 0.9
},
"target": {
"file": "include/VendorVideoAPI.h"
},
"id": "PUB-A-252764175-7e3dc673",
"source": "https://android.googlesource.com/platform/hardware/google/gchips/+/75c487c45a40ca66a06722f5ac12b1ece58a6b13",
"signature_version": "v1"
},
{
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"182581172807498517608401806623847762445",
"11734651323018246883399799883219691364",
"266436673382873636585565935850219384440",
"19386917035829971824956363680145203155",
"288003666696654638328961736625138323395",
"85840979306919565775277901674338052279",
"152527333130694181612170269090986399465",
"80790618311609125044124225089649877823",
"270346060247846624672571195924028765095",
"33660464860934763414305455328277954554",
"33946360768637044135657392035522294030",
"61620501149699977937125441982614459110",
"32684410621382859336984223246472034650",
"33946360768637044135657392035522294030",
"13247480742606314829716838518395668137",
"262098992046344821039630075497884059640",
"179864163034560385696888305030676015417",
"145809841884496083078556997948750453326",
"152395261160673331840195020486129164802",
"179864163034560385696888305030676015417",
"325945144054238968896047093285361532052",
"304225207605109204168887291160787572234",
"319501023042922402153059086597335407461",
"159214689713902825530149059629368024251",
"186901356770420397951548660752940876857",
"244313220130784846847259821300365251009",
"31317059182051608271978482473922971815",
"110188320612106258763584006334517208790",
"210713506797445088746877259943475093595",
"112484420503486617211934826343972246552",
"110188320612106258763584006334517208790",
"210713506797445088746877259943475093595",
"112484420503486617211934826343972246552",
"110188320612106258763584006334517208790",
"210713506797445088746877259943475093595",
"112484420503486617211934826343972246552",
"110188320612106258763584006334517208790",
"210713506797445088746877259943475093595",
"112484420503486617211934826343972246552",
"110188320612106258763584006334517208790",
"210713506797445088746877259943475093595",
"112484420503486617211934826343972246552",
"110188320612106258763584006334517208790",
"210713506797445088746877259943475093595",
"330259678526029788509620435184499620251",
"110188320612106258763584006334517208790",
"210713506797445088746877259943475093595",
"112484420503486617211934826343972246552",
"110188320612106258763584006334517208790",
"210713506797445088746877259943475093595",
"112484420503486617211934826343972246552",
"110188320612106258763584006334517208790",
"210713506797445088746877259943475093595",
"112484420503486617211934826343972246552",
"120942857288381002852597434989115660433",
"275493013820668439920356266637882257447",
"219492985612179803867596211322350236243",
"59477089528546236320147109623844776249",
"106460817617930475041626093317668281215",
"125322326058517183634965844799914044909",
"110240825417115269777647375628212457328",
"187583686202245783351211899941031975792",
"7671754239627284804603445693178513826",
"126647991437013121257745274504992121078",
"261514594185540503638660574829702249280",
"152041810455952622627236188051328465373",
"103373564408305994517647250133044901726",
"160812034451585017636066300276746359897",
"198831218778292002441035499901786450816",
"22740232837694339387843830000702153804",
"141607784771605399765196754791404032742",
"50717844565559979798427721093410995763",
"205510126907339749437929707324847666724",
"141012099670024970752573004475745895275",
"320458251671449027703914301236617737252",
"47100071524393611381470928968400398431",
"306294789558957001975715049793198574708",
"95146758386217588282554966661694649619",
"2790904118096634903747996284435429850",
"319313499476516637128688107104994122249",
"239045051439653467931547038148428388931",
"297262468073345917982998286631452146715",
"6959121070700111077951293582189301929",
"297277200207526974590242025121621882512",
"312147725916819792703572107303029950323",
"10285174281797203395588908926924803325",
"146362284262287164678858588001875885560",
"46523761035060979686672839801417850303",
"195397904603323606510188956832964719920",
"151073062314279471555630643694602436338",
"104725654548847444279445766802944262851",
"80993537639332918525421878960789773769",
"8440176370682357733091315649889868951",
"250448007869784050030308439362120104627",
"57876713925441944854557814696809063800",
"252873137281053868206589352714562477442",
"300466616345882195784406469387757501158",
"135405098076047921133490758297403524872",
"154959885755073886255498922414777428733",
"4413272464025526173143633847668838453",
"237144129241424600796003490851335604557",
"18644651554331601872032500268853941861",
"181701674773739700419994106407988956121",
"22740232837694339387843830000702153804",
"140977749603402487362215160172092447236",
"213050748734336018794470702406026544125",
"59109373342793278909991985602419069527",
"90104006538887231453862090675011793267",
"153591530344519563061509772176348860395",
"56050925349642354360165005546180533419",
"130231737081769903503307162845919939260",
"30932856217059918012668191635085404650",
"134063287533457897717814201822041992854",
"304851110619612092425465112514433583268",
"305051545562225504571446997134115785041",
"224313964342440091232689672665833587506",
"132227836804176995926133909691950248538",
"180302646706919952371342405196850873125",
"298051276773135892925158575066269666822",
"201288569560187549111297559967828231368",
"126452061617654159714251472699191698941",
"297277200207526974590242025121621882512",
"24931609180649960367746021185846934000",
"155894473670099304263900294117928435555",
"133512013890906109358866347731190024887",
"92580573049066031862215944186885043372",
"78078928536598151618056313275294089540",
"286445533549120577818045022167036684514",
"203562541634497943637843188231609112545",
"276912660912125857277703369520448481523",
"281384267367864252862755508333228521208",
"196583552427474544808922054667673602272",
"135170623709712571059308874047898000977"
],
"threshold": 0.9
},
"source": "https://android.googlesource.com/platform/hardware/google/gchips/+/75c487c45a40ca66a06722f5ac12b1ece58a6b13",
"target": {
"file": "videoapi/VendorVideoAPI.cpp"
},
"id": "PUB-A-252764175-b50fed88"
}
],
"severity": "Moderate"
}{
"spl": "2023-06-01",
"fixes": [
"https://android.googlesource.com/platform/hardware/google/graphics/common/+/31ad515db643b6873fed25952b3172aaf8161761"
],
"types": [
"ID"
],
"vanir_signatures": [
{
"match_only_versions": [
"13"
],
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 785.0,
"function_hash": "269051373921565162815233825939761381396"
},
"target": {
"function": "ExynosLayer::setLayerPerFrameMetadataBlobs",
"file": "libhwc2.1/libdevice/ExynosLayer.cpp"
},
"id": "PUB-A-252764175-31a26465",
"source": "https://android.googlesource.com/platform/hardware/google/graphics/common/+/31ad515db643b6873fed25952b3172aaf8161761",
"signature_version": "v1"
},
{
"match_only_versions": [
"13"
],
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"288494675835549734070512860694294321778",
"266720710589569744280202702541864478273",
"50975389984735270905780513613223602051",
"129847710924168018784424963183918388059"
],
"threshold": 0.9
},
"target": {
"file": "libhwc2.1/libdevice/ExynosLayer.cpp"
},
"id": "PUB-A-252764175-de64dab6",
"source": "https://android.googlesource.com/platform/hardware/google/graphics/common/+/31ad515db643b6873fed25952b3172aaf8161761",
"signature_version": "v1"
}
],
"severity": "Moderate"
}