{"id":"ASB-A-182152757","details":"In ih264d_mark_err_slice_skip of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.","aliases":["A-182152757","CVE-2021-0690"],"modified":"2026-04-20T15:37:26.169566Z","published":"2021-09-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2021-09-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/external/libavc/+/fa13b3087684ffefd82d61c34e61714881674cd3"}],"affected":[{"package":{"name":"platform/external/libavc","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.1:0"},{"fixed":"8.1:2021-09-01"}]}],"versions":["8.1"],"ecosystem_specific":{"spl":"2021-09-01","vanir_signatures":[{"signature_type":"Function","deprecated":false,"signature_version":"v1","id":"ASB-A-182152757-2fede1f9","target":{"function":"ih264d_parse_decode_slice","file":"decoder/ih264d_parse_slice.c"},"source":"https://android.googlesource.com/platform/external/libavc/+/a88e0683a420d7ee9aa4b6f41f94cb8dc0c5e040","digest":{"length":16825,"function_hash":"123133853663000408978406452059135005748"}},{"signature_type":"Line","deprecated":false,"signature_version":"v1","id":"ASB-A-182152757-c614f4a9","target":{"file":"decoder/ih264d_parse_slice.c"},"source":"https://android.googlesource.com/platform/external/libavc/+/a88e0683a420d7ee9aa4b6f41f94cb8dc0c5e040","digest":{"line_hashes":["119945963440541538035784979728125816983","255224296024612985390484146779658378250","160388031835788071854010997219348523817","60516511112450173609462386312560336575","63902476905212605000620325702263251555","275929453535975115840424296357929607942","254429859499802782634724683805821366471","154945095007020849168726000600056374878","107239300484544486887623642710182168076","328091311931346925764590564347209009119","9674616957337096999271654405362951351","329916013161882525599151527348539263851"],"threshold":0.9}}],"severity":"High","types":["ID"],"fixes":["https://android.googlesource.com/platform/external/libavc/+/a88e0683a420d7ee9aa4b6f41f94cb8dc0c5e040"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-182152757.json"}},{"package":{"name":"platform/external/libavc","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9:0"},{"fixed":"9:2021-09-01"}]}],"versions":["9"],"ecosystem_specific":{"spl":"2021-09-01","vanir_signatures":[{"signature_type":"Function","deprecated":false,"signature_version":"v1","id":"ASB-A-182152757-b3fb194d","target":{"function":"ih264d_parse_decode_slice","file":"decoder/ih264d_parse_slice.c"},"source":"https://android.googlesource.com/platform/external/libavc/+/a88e0683a420d7ee9aa4b6f41f94cb8dc0c5e040","digest":{"length":16825,"function_hash":"123133853663000408978406452059135005748"}},{"signature_type":"Line","deprecated":false,"signature_version":"v1","id":"ASB-A-182152757-ef6c7100","target":{"file":"decoder/ih264d_parse_slice.c"},"source":"https://android.googlesource.com/platform/external/libavc/+/a88e0683a420d7ee9aa4b6f41f94cb8dc0c5e040","digest":{"line_hashes":["119945963440541538035784979728125816983","255224296024612985390484146779658378250","160388031835788071854010997219348523817","60516511112450173609462386312560336575","63902476905212605000620325702263251555","275929453535975115840424296357929607942","254429859499802782634724683805821366471","154945095007020849168726000600056374878","107239300484544486887623642710182168076","328091311931346925764590564347209009119","9674616957337096999271654405362951351","329916013161882525599151527348539263851"],"threshold":0.9}}],"severity":"High","types":["ID"],"fixes":["https://android.googlesource.com/platform/external/libavc/+/a88e0683a420d7ee9aa4b6f41f94cb8dc0c5e040"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-182152757.json"}},{"package":{"name":"platform/external/libavc","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10:0"},{"fixed":"10:2021-09-01"}]}],"versions":["10"],"ecosystem_specific":{"spl":"2021-09-01","vanir_signatures":[{"signature_type":"Function","deprecated":false,"signature_version":"v1","id":"ASB-A-182152757-330580d9","target":{"function":"ih264d_parse_decode_slice","file":"decoder/ih264d_parse_slice.c"},"source":"https://android.googlesource.com/platform/external/libavc/+/a88e0683a420d7ee9aa4b6f41f94cb8dc0c5e040","digest":{"length":16825,"function_hash":"123133853663000408978406452059135005748"}},{"signature_type":"Line","deprecated":false,"signature_version":"v1","id":"ASB-A-182152757-4952bf04","target":{"file":"decoder/ih264d_parse_slice.c"},"source":"https://android.googlesource.com/platform/external/libavc/+/a88e0683a420d7ee9aa4b6f41f94cb8dc0c5e040","digest":{"line_hashes":["119945963440541538035784979728125816983","255224296024612985390484146779658378250","160388031835788071854010997219348523817","60516511112450173609462386312560336575","63902476905212605000620325702263251555","275929453535975115840424296357929607942","254429859499802782634724683805821366471","154945095007020849168726000600056374878","107239300484544486887623642710182168076","328091311931346925764590564347209009119","9674616957337096999271654405362951351","329916013161882525599151527348539263851"],"threshold":0.9}}],"severity":"High","types":["ID"],"fixes":["https://android.googlesource.com/platform/external/libavc/+/a88e0683a420d7ee9aa4b6f41f94cb8dc0c5e040"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-182152757.json"}},{"package":{"name":"platform/external/libavc","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11:0"},{"fixed":"11:2021-09-01"}]}],"versions":["11"],"ecosystem_specific":{"spl":"2021-09-01","vanir_signatures":[{"signature_type":"Function","deprecated":false,"signature_version":"v1","id":"ASB-A-182152757-acac14b4","target":{"function":"ih264d_parse_decode_slice","file":"decoder/ih264d_parse_slice.c"},"source":"https://android.googlesource.com/platform/external/libavc/+/a88e0683a420d7ee9aa4b6f41f94cb8dc0c5e040","digest":{"length":16825,"function_hash":"123133853663000408978406452059135005748"}},{"signature_type":"Line","deprecated":false,"signature_version":"v1","id":"ASB-A-182152757-de88befd","target":{"file":"decoder/ih264d_parse_slice.c"},"source":"https://android.googlesource.com/platform/external/libavc/+/a88e0683a420d7ee9aa4b6f41f94cb8dc0c5e040","digest":{"line_hashes":["119945963440541538035784979728125816983","255224296024612985390484146779658378250","160388031835788071854010997219348523817","60516511112450173609462386312560336575","63902476905212605000620325702263251555","275929453535975115840424296357929607942","254429859499802782634724683805821366471","154945095007020849168726000600056374878","107239300484544486887623642710182168076","328091311931346925764590564347209009119","9674616957337096999271654405362951351","329916013161882525599151527348539263851"],"threshold":0.9}}],"severity":"High","types":["ID"],"fixes":["https://android.googlesource.com/platform/external/libavc/+/a88e0683a420d7ee9aa4b6f41f94cb8dc0c5e040"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-182152757.json"}}],"schema_version":"1.7.5"}