PUB-A-176495665
Dashboard / Vulnerabilities / PUB-A-176495665
Summary:
Details: In decrypt of CryptoPlugin.cpp, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
References: https://source.android.com/security/bulletin/2021-06-01, https://android.googlesource.com/platform/frameworks/av/+/79a6ffbdaf14cfbb597efd8545ba401f1da28a4f, https://android.googlesource.com/platform/frameworks/av/+/abb7ad47b00ae158eded8813801345d91d2b2671, https://android.googlesource.com/platform/hardware/interfaces/+/a4e76aab230a565dd0cef11e2e6e2d782b685327, https://android.googlesource.com/platform/hardware/interfaces/+/9fcd4886a3e1ccbc18acfadd84906400c9882eda
Affected packages
Package
Name: platform/frameworks/av
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
