In icmpglobalallow of icmp.c, there is a possible disclosure of UDP source ports due to a side channel information disclosure. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "severity": "High", "fixes": [ "https://android.googlesource.com/kernel/common/+/d6c552505c0d1719dda42b4af2def0618bd7bf54" ], "types": [ "ID" ], "vanir_signatures": [ { "id": "ASB-A-174737972-43743423", "deprecated": false, "signature_type": "Line", "signature_version": "v1", "target": { "file": "net/ipv4/icmp.c" }, "digest": { "line_hashes": [ "163913056625793112109650011569155398386", "210684640381025930440861970689826949797", "209938629944047462960407534985341434993", "40753138780160875603608046948079932055", "297873878207537430882684102534028570754", "308012898973444846626945894151657072823", "230341944539684975838520879358771435882" ], "threshold": 0.9 }, "source": "https://android.googlesource.com/kernel/common/+/d6c552505c0d1719dda42b4af2def0618bd7bf54" }, { "id": "ASB-A-174737972-4bb1e52a", "deprecated": false, "signature_type": "Function", "signature_version": "v1", "target": { "function": "icmp_global_allow", "file": "net/ipv4/icmp.c" }, "digest": { "function_hash": "319530313875119990490265042306097655903", "length": 676.0 }, "source": "https://android.googlesource.com/kernel/common/+/d6c552505c0d1719dda42b4af2def0618bd7bf54" } ], "spl": "2021-04-05" }