In parseUsesPermission of ParsingPackageUtils.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "233468297413593397394297712448269979643", "70811960205434562314080175780461273895", "22439025937987995327133908070800259810", "104471443701088480886602663194600715996", "298499600960742821919062986980661044130", "95891512518350473598574258831346876298", "74461255058017342824900763743093953044" ] }, "id": "ASB-A-259942609-bdc3ae43", "source": "https://android.googlesource.com/platform/frameworks/base/+/b7d62363d2bd1e2f25a07e72753da0189985ba67", "deprecated": true, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/pm/pkg/parsing/ParsingPackageUtils.java" }, "signature_type": "Line" }, { "digest": { "length": 3196.0, "function_hash": "294343802404084889054637398552666988383" }, "id": "ASB-A-259942609-c9fe3c00", "source": "https://android.googlesource.com/platform/frameworks/base/+/b7d62363d2bd1e2f25a07e72753da0189985ba67", "deprecated": true, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/pm/pkg/parsing/ParsingPackageUtils.java", "function": "parseUsesPermission" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/b7d62363d2bd1e2f25a07e72753da0189985ba67" ], "spl": "2023-04-01", "severity": "High", "types": [ "DoS" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "233468297413593397394297712448269979643", "70811960205434562314080175780461273895", "22439025937987995327133908070800259810", "104471443701088480886602663194600715996", "174378944264573247603940444631810033873", "17188419640653343995655913053254468102", "177124981143631127301714150448223349963" ] }, "id": "ASB-A-259942609-65c591dd", "source": "https://android.googlesource.com/platform/frameworks/base/+/de8ef32d020ce4efe5dcaae09c9b8e0cf7efb2db", "deprecated": true, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/pm/pkg/parsing/ParsingPackageUtils.java" }, "signature_type": "Line" }, { "digest": { "length": 3177.0, "function_hash": "160205189274907442256872566515021715710" }, "id": "ASB-A-259942609-ac85a82d", "source": "https://android.googlesource.com/platform/frameworks/base/+/de8ef32d020ce4efe5dcaae09c9b8e0cf7efb2db", "deprecated": true, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/pm/pkg/parsing/ParsingPackageUtils.java", "function": "parseUsesPermission" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/de8ef32d020ce4efe5dcaae09c9b8e0cf7efb2db" ], "spl": "2023-04-01", "severity": "High", "types": [ "DoS" ] }