In icmpglobalallow of icmp.c, there is a possible disclosure of UDP source ports due to a side channel information disclosure. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "163913056625793112109650011569155398386", "210684640381025930440861970689826949797", "209938629944047462960407534985341434993", "40753138780160875603608046948079932055", "297873878207537430882684102534028570754", "308012898973444846626945894151657072823", "230341944539684975838520879358771435882" ] }, "id": "ASB-A-174737972-43743423", "source": "https://android.googlesource.com/kernel/common/+/d6c552505c0d1719dda42b4af2def0618bd7bf54", "deprecated": false, "signature_version": "v1", "target": { "file": "net/ipv4/icmp.c" }, "signature_type": "Line" }, { "digest": { "length": 676.0, "function_hash": "319530313875119990490265042306097655903" }, "id": "ASB-A-174737972-4bb1e52a", "source": "https://android.googlesource.com/kernel/common/+/d6c552505c0d1719dda42b4af2def0618bd7bf54", "deprecated": false, "signature_version": "v1", "target": { "file": "net/ipv4/icmp.c", "function": "icmp_global_allow" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/kernel/common/+/d6c552505c0d1719dda42b4af2def0618bd7bf54" ], "spl": "2021-04-05", "severity": "High", "types": [ "ID" ] }