In dev_config of inode.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"spl": "2022-06-05",
"severity": "High",
"types": [
"EoP"
],
"vanir_signatures": [
{
"id": "ASB-A-220261709-0c87b34c",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "dev_config",
"truncated_path_level": 1.0,
"file": "drivers/usb/gadget/legacy/inode.c"
},
"digest": {
"length": 2092.0,
"function_hash": "100910238043098768575891757463404886640"
},
"signature_type": "Function",
"source": "https://android.googlesource.com/kernel/common/+/590a98d5d1086"
},
{
"id": "ASB-A-220261709-383a2aa8",
"deprecated": false,
"signature_version": "v1",
"target": {
"truncated_path_level": 1.0,
"file": "drivers/usb/gadget/legacy/inode.c"
},
"digest": {
"line_hashes": [
"186639761942567450573979788117275880424",
"333096429839334311930049144006513742060",
"60719391462526005632700289665433177534",
"317186749981178857477562520181006939674",
"54064079988113171740121196451130712801",
"43619927766329838885358180382763708978",
"79775120953513019826931127321861343923",
"132156066930817037200589357825327870347",
"218457760794979473464887387052798417883"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://android.googlesource.com/kernel/common/+/fdd64084e4055"
},
{
"id": "ASB-A-220261709-6f47482d",
"deprecated": false,
"signature_version": "v1",
"target": {
"truncated_path_level": 1.0,
"file": "drivers/usb/gadget/legacy/inode.c"
},
"digest": {
"line_hashes": [
"186639761942567450573979788117275880424",
"333096429839334311930049144006513742060",
"60719391462526005632700289665433177534",
"317186749981178857477562520181006939674",
"54064079988113171740121196451130712801",
"43619927766329838885358180382763708978",
"79775120953513019826931127321861343923",
"132156066930817037200589357825327870347",
"218457760794979473464887387052798417883"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://android.googlesource.com/kernel/common/+/590a98d5d1086"
},
{
"id": "ASB-A-220261709-82a60387",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "dev_config",
"truncated_path_level": 1.0,
"file": "drivers/usb/gadget/legacy/inode.c"
},
"digest": {
"length": 2092.0,
"function_hash": "100910238043098768575891757463404886640"
},
"signature_type": "Function",
"source": "https://android.googlesource.com/kernel/common/+/c13159a588818"
},
{
"id": "ASB-A-220261709-87ae7b2c",
"deprecated": false,
"signature_version": "v1",
"target": {
"truncated_path_level": 1.0,
"file": "drivers/usb/gadget/legacy/inode.c"
},
"digest": {
"line_hashes": [
"203430003165072718367858077295931742840",
"180273471412337465156164558445533312811",
"131691568141789193167961131358887418833",
"296795267979675987565603514620564612986",
"88886914578469651870350528706792891694",
"230937538168488276498676548176124459417"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://android.googlesource.com/kernel/common/+/ff0000fe82f45"
},
{
"id": "ASB-A-220261709-af9535f3",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "dev_config",
"truncated_path_level": 1.0,
"file": "drivers/usb/gadget/legacy/inode.c"
},
"digest": {
"length": 2152.0,
"function_hash": "142784419688723226106187868832514389771"
},
"signature_type": "Function",
"source": "https://android.googlesource.com/kernel/common/+/ff0000fe82f45"
},
{
"id": "ASB-A-220261709-c3d603db",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "dev_config",
"truncated_path_level": 1.0,
"file": "drivers/usb/gadget/legacy/inode.c"
},
"digest": {
"length": 2122.0,
"function_hash": "280494176015748101793496394995502174323"
},
"signature_type": "Function",
"source": "https://android.googlesource.com/kernel/common/+/fdd64084e4055"
},
{
"id": "ASB-A-220261709-dbf6ae12",
"deprecated": false,
"signature_version": "v1",
"target": {
"truncated_path_level": 1.0,
"file": "drivers/usb/gadget/legacy/inode.c"
},
"digest": {
"line_hashes": [
"203430003165072718367858077295931742840",
"180273471412337465156164558445533312811",
"131691568141789193167961131358887418833",
"296795267979675987565603514620564612986",
"88886914578469651870350528706792891694",
"230937538168488276498676548176124459417"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://android.googlesource.com/kernel/common/+/c13159a588818"
}
],
"fixes": [
"https://android.googlesource.com/kernel/common/+/ff0000fe82f45",
"https://android.googlesource.com/kernel/common/+/590a98d5d1086",
"https://android.googlesource.com/kernel/common/+/c13159a588818",
"https://android.googlesource.com/kernel/common/+/fdd64084e4055"
]
}