In binder_transaction of binder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "length": 18013.0, "function_hash": "104350902273562953596098694912734147909" }, "id": "ASB-A-352520660-2ac62b41", "source": "https://android.googlesource.com/kernel/common/+/c2201dde2a76788b5b7a75426e53a58e1490a028", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/android/binder.c", "function": "binder_transaction" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "51888937389919906871644406365993764050", "315719652939985718370173453336879978828", "306596573906054325073390756280075125039", "132267424506088119725110653472980559623" ] }, "id": "ASB-A-352520660-35c21aa1", "source": "https://android.googlesource.com/kernel/common/+/b42ed94769088450987f2b52f41a3fb274244827", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/android/binder.c" }, "signature_type": "Line" }, { "digest": { "threshold": 0.9, "line_hashes": [ "51888937389919906871644406365993764050", "315719652939985718370173453336879978828", "306596573906054325073390756280075125039", "132267424506088119725110653472980559623" ] }, "id": "ASB-A-352520660-3ce7c5be", "source": "https://android.googlesource.com/kernel/common/+/f4e5b5151e55932279287c55d4e4a801fbf1df96", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/android/binder.c" }, "signature_type": "Line" }, { "digest": { "length": 17774.0, "function_hash": "12085335973923029868560151051282433776" }, "id": "ASB-A-352520660-4caecefe", "source": "https://android.googlesource.com/kernel/common/+/f4e5b5151e55932279287c55d4e4a801fbf1df96", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/android/binder.c", "function": "binder_transaction" }, "signature_type": "Function" }, { "digest": { "length": 20332.0, "function_hash": "235222454460835599941035140580137942606" }, "id": "ASB-A-352520660-51de2d94", "source": "https://android.googlesource.com/kernel/common/+/b42ed94769088450987f2b52f41a3fb274244827", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/android/binder.c", "function": "binder_transaction" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "51888937389919906871644406365993764050", "315719652939985718370173453336879978828", "306596573906054325073390756280075125039", "132267424506088119725110653472980559623" ] }, "id": "ASB-A-352520660-52a0d742", "source": "https://android.googlesource.com/kernel/common/+/c2201dde2a76788b5b7a75426e53a58e1490a028", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/android/binder.c" }, "signature_type": "Line" }, { "digest": { "threshold": 0.9, "line_hashes": [ "51888937389919906871644406365993764050", "315719652939985718370173453336879978828", "306596573906054325073390756280075125039", "132267424506088119725110653472980559623" ] }, "id": "ASB-A-352520660-54fb9111", "source": "https://android.googlesource.com/kernel/common/+/370ea8bc2e0b1c4880c41bbfc2b01bac973209b9", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/android/binder.c" }, "signature_type": "Line" }, { "digest": { "threshold": 0.9, "line_hashes": [ "51888937389919906871644406365993764050", "315719652939985718370173453336879978828", "306596573906054325073390756280075125039", "132267424506088119725110653472980559623" ] }, "id": "ASB-A-352520660-57f8b180", "source": "https://android.googlesource.com/kernel/common/+/ae7e5da1cae2b6be45f7c6ab6a70d35f6e532d5a", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/android/binder.c" }, "signature_type": "Line" }, { "digest": { "length": 18055.0, "function_hash": "26201428169686979003502332237103000119" }, "id": "ASB-A-352520660-80d84122", "source": "https://android.googlesource.com/kernel/common/+/135a19cfad1e5e9c1db63970df743c28f5dd74c8", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/android/binder.c", "function": "binder_transaction" }, "signature_type": "Function" }, { "digest": { "length": 18269.0, "function_hash": "134030630356211660644016878613318183524" }, "id": "ASB-A-352520660-8116079d", "source": "https://android.googlesource.com/kernel/common/+/6a1de5f5d37141467efb9e5d9b3844a19f9990a9", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/android/binder.c", "function": "binder_transaction" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "51888937389919906871644406365993764050", "315719652939985718370173453336879978828", "306596573906054325073390756280075125039", "132267424506088119725110653472980559623" ] }, "id": "ASB-A-352520660-811c79d9", "source": "https://android.googlesource.com/kernel/common/+/30efc10dfe20bbf7410adb3d756106f365ac75cc", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/android/binder.c" }, "signature_type": "Line" }, { "digest": { "length": 18187.0, "function_hash": "266630354378468398294554775889965658084" }, "id": "ASB-A-352520660-9bfe6af8", "source": "https://android.googlesource.com/kernel/common/+/ae7e5da1cae2b6be45f7c6ab6a70d35f6e532d5a", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/android/binder.c", "function": "binder_transaction" }, "signature_type": "Function" }, { "digest": { "length": 20220.0, "function_hash": "335815782176887932271238368181408598136" }, "id": "ASB-A-352520660-d0dc8d2a", "source": "https://android.googlesource.com/kernel/common/+/370ea8bc2e0b1c4880c41bbfc2b01bac973209b9", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/android/binder.c", "function": "binder_transaction" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "51888937389919906871644406365993764050", "315719652939985718370173453336879978828", "306596573906054325073390756280075125039", "132267424506088119725110653472980559623" ] }, "id": "ASB-A-352520660-da87085d", "source": "https://android.googlesource.com/kernel/common/+/135a19cfad1e5e9c1db63970df743c28f5dd74c8", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/android/binder.c" }, "signature_type": "Line" }, { "digest": { "threshold": 0.9, "line_hashes": [ "51888937389919906871644406365993764050", "315719652939985718370173453336879978828", "306596573906054325073390756280075125039", "132267424506088119725110653472980559623" ] }, "id": "ASB-A-352520660-eb42badc", "source": "https://android.googlesource.com/kernel/common/+/6a1de5f5d37141467efb9e5d9b3844a19f9990a9", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/android/binder.c" }, "signature_type": "Line" }, { "digest": { "length": 18521.0, "function_hash": "256859784912828081331698653568560448651" }, "id": "ASB-A-352520660-ff81ab80", "source": "https://android.googlesource.com/kernel/common/+/30efc10dfe20bbf7410adb3d756106f365ac75cc", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/android/binder.c", "function": "binder_transaction" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/kernel/common/+/f4e5b5151e55932279287c55d4e4a801fbf1df96", "https://android.googlesource.com/kernel/common/+/135a19cfad1e5e9c1db63970df743c28f5dd74c8", "https://android.googlesource.com/kernel/common/+/c2201dde2a76788b5b7a75426e53a58e1490a028", "https://android.googlesource.com/kernel/common/+/6a1de5f5d37141467efb9e5d9b3844a19f9990a9", "https://android.googlesource.com/kernel/common/+/ae7e5da1cae2b6be45f7c6ab6a70d35f6e532d5a", "https://android.googlesource.com/kernel/common/+/30efc10dfe20bbf7410adb3d756106f365ac75cc", "https://android.googlesource.com/kernel/common/+/370ea8bc2e0b1c4880c41bbfc2b01bac973209b9", "https://android.googlesource.com/kernel/common/+/b42ed94769088450987f2b52f41a3fb274244827" ], "spl": "2024-11-05", "severity": "High", "types": [ "EoP" ] }