{"id":"ASB-A-203938029","details":"In LoadedPackage::Load of LoadedArsc.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure when parsing an APK file with no additional execution privileges needed. User interaction is needed for exploitation.","aliases":["A-203938029","CVE-2021-39664"],"modified":"2026-09-18T15:47:37.392928379Z","published":"2022-02-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2022-02-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/frameworks/base/+/18c66d8fee0e0dd8681182a59b59119a21e09c0c"}],"affected":[{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12:0"},{"fixed":"12:2022-02-01"}]}],"versions":["12"],"ecosystem_specific":{"vanir_signatures":[{"source":"https://android.googlesource.com/platform/frameworks/base/+/a27822a79554c8cd875eac826ab84f550a7ea006","target":{"file":"libs/androidfw/LoadedArsc.cpp","function":"LoadedPackage::Load"},"deprecated":false,"digest":{"length":9123,"function_hash":"181116009843264885544175333191855524801"},"id":"ASB-A-203938029-7597b1d4","signature_type":"Function","signature_version":"v1"},{"target":{"file":"libs/androidfw/LoadedArsc.cpp"},"deprecated":false,"digest":{"line_hashes":["88503139530149035342909553538189157400","179056582815394341313746471977935240601","328373188247067051346367725971177865524","32852578828518611587623288540746871338"],"threshold":0.9},"id":"ASB-A-203938029-e930b640","signature_type":"Line","signature_version":"v1","source":"https://android.googlesource.com/platform/frameworks/base/+/a27822a79554c8cd875eac826ab84f550a7ea006"}],"fixes":["https://android.googlesource.com/platform/frameworks/base/+/a27822a79554c8cd875eac826ab84f550a7ea006"],"severity":"High","spl":"2022-02-01","types":["ID"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-203938029.json"}}],"schema_version":"1.9.0"}