In legacyparseparam of fs_context.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
{ "severity": "Moderate", "fixes": [ "https://android.googlesource.com/kernel/common/+/a32e89883a535", "https://android.googlesource.com/kernel/common/+/eadde287a62e6" ], "types": [ "EoP" ], "vanir_signatures": [ { "id": "PUB-A-213172369-44cea301", "deprecated": false, "signature_type": "Line", "signature_version": "v1", "target": { "file": "fs/fs_context.c" }, "digest": { "line_hashes": [ "332611879140404434690152632347982780701", "193005555054335394959908412522152239921", "308843018842959193664841224512432202885", "251322244919373171567936309461685841974" ], "threshold": 0.9 }, "source": "https://android.googlesource.com/kernel/common/+/a32e89883a535" }, { "id": "PUB-A-213172369-4d2f18b1", "deprecated": false, "signature_type": "Function", "signature_version": "v1", "target": { "function": "legacy_parse_param", "file": "fs/fs_context.c" }, "digest": { "function_hash": "67543043462929298139978757926468672210", "length": 1796.0 }, "source": "https://android.googlesource.com/kernel/common/+/a32e89883a535" }, { "id": "PUB-A-213172369-a492c0a0", "deprecated": false, "signature_type": "Line", "signature_version": "v1", "target": { "file": "fs/fs_context.c" }, "digest": { "line_hashes": [ "332611879140404434690152632347982780701", "193005555054335394959908412522152239921", "308843018842959193664841224512432202885", "251322244919373171567936309461685841974" ], "threshold": 0.9 }, "source": "https://android.googlesource.com/kernel/common/+/eadde287a62e6" }, { "id": "PUB-A-213172369-aad49fbf", "deprecated": false, "signature_type": "Function", "signature_version": "v1", "target": { "function": "legacy_parse_param", "file": "fs/fs_context.c" }, "digest": { "function_hash": "67543043462929298139978757926468672210", "length": 1796.0 }, "source": "https://android.googlesource.com/kernel/common/+/eadde287a62e6" } ], "spl": "2022-06-05" }