{"id":"ASB-A-264880689","details":"In update of MmsProvider.java, there is a possible way to bypass file permission checks due to a race condition. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-264880689","CVE-2023-21290"],"modified":"2026-05-22T15:55:21.353668239Z","published":"2023-08-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2023-08-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/ca4c9a19635119d95900793e7a41b820cd1d94d9"}],"affected":[{"package":{"name":"platform/packages/providers/TelephonyProvider","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13-next:0"},{"fixed":"13-next:2023-08-01"}]}],"versions":["13-next"],"ecosystem_specific":{"vanir_signatures":[{"id":"ASB-A-264880689-684bfacc","source":"https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c","signature_type":"Function","deprecated":false,"digest":{"function_hash":"157104286834053058667808334963109926916","length":2447},"target":{"file":"src/com/android/providers/telephony/MmsProvider.java","function":"update"},"signature_version":"v1"},{"id":"ASB-A-264880689-dfbed74f","source":"https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c","signature_type":"Line","deprecated":false,"digest":{"threshold":0.9,"line_hashes":["281253907639525144025299373930782407033","132876137314617094737140570055861165390","4690526999091256758990293462794369238","7544939645273274879206324847218671046","12071255814901493088040976794853679443","164998211426005178073519557115678279380","224677706242864877018902563102024141642","33215650706164921697314748434731617263","123209350887477386788433845434072400276","9931110887952007559812108128041600154","214728215846428908470951434899761443372","278832171060732843206969616038814260467"]},"target":{"file":"src/com/android/providers/telephony/MmsProvider.java"},"signature_version":"v1"}],"spl":"2023-08-01","severity":"High","types":["DoS"],"fixes":["https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-264880689.json"}},{"package":{"name":"platform/packages/providers/TelephonyProvider","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11:0"},{"fixed":"11:2023-08-01"}]}],"versions":["11"],"ecosystem_specific":{"vanir_signatures":[{"id":"ASB-A-264880689-0825b9fe","signature_type":"Function","source":"https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c","deprecated":false,"digest":{"function_hash":"157104286834053058667808334963109926916","length":2447},"target":{"function":"update","file":"src/com/android/providers/telephony/MmsProvider.java"},"signature_version":"v1"},{"id":"ASB-A-264880689-8bbb028b","signature_type":"Line","source":"https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c","deprecated":false,"digest":{"threshold":0.9,"line_hashes":["281253907639525144025299373930782407033","132876137314617094737140570055861165390","4690526999091256758990293462794369238","7544939645273274879206324847218671046","12071255814901493088040976794853679443","164998211426005178073519557115678279380","224677706242864877018902563102024141642","33215650706164921697314748434731617263","123209350887477386788433845434072400276","9931110887952007559812108128041600154","214728215846428908470951434899761443372","278832171060732843206969616038814260467"]},"target":{"file":"src/com/android/providers/telephony/MmsProvider.java"},"signature_version":"v1"}],"spl":"2023-08-01","severity":"High","types":["DoS"],"fixes":["https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-264880689.json"}},{"package":{"name":"platform/packages/providers/TelephonyProvider","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12:0"},{"fixed":"12:2023-08-01"}]}],"versions":["12"],"ecosystem_specific":{"vanir_signatures":[{"id":"ASB-A-264880689-65fd960f","source":"https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c","signature_type":"Line","deprecated":false,"digest":{"threshold":0.9,"line_hashes":["281253907639525144025299373930782407033","132876137314617094737140570055861165390","4690526999091256758990293462794369238","7544939645273274879206324847218671046","12071255814901493088040976794853679443","164998211426005178073519557115678279380","224677706242864877018902563102024141642","33215650706164921697314748434731617263","123209350887477386788433845434072400276","9931110887952007559812108128041600154","214728215846428908470951434899761443372","278832171060732843206969616038814260467"]},"target":{"file":"src/com/android/providers/telephony/MmsProvider.java"},"signature_version":"v1"},{"id":"ASB-A-264880689-8d4acadd","source":"https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c","signature_type":"Function","deprecated":false,"digest":{"function_hash":"157104286834053058667808334963109926916","length":2447},"target":{"function":"update","file":"src/com/android/providers/telephony/MmsProvider.java"},"signature_version":"v1"}],"spl":"2023-08-01","severity":"High","types":["DoS"],"fixes":["https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-264880689.json"}},{"package":{"name":"platform/packages/providers/TelephonyProvider","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12L:0"},{"fixed":"12L:2023-08-01"}]}],"versions":["12L"],"ecosystem_specific":{"spl":"2023-08-01","vanir_signatures":[{"id":"ASB-A-264880689-bd1a1eaf","source":"https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c","signature_type":"Function","deprecated":false,"digest":{"function_hash":"157104286834053058667808334963109926916","length":2447},"target":{"function":"update","file":"src/com/android/providers/telephony/MmsProvider.java"},"signature_version":"v1"},{"id":"ASB-A-264880689-c4fc9a17","source":"https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c","signature_type":"Line","deprecated":false,"digest":{"threshold":0.9,"line_hashes":["281253907639525144025299373930782407033","132876137314617094737140570055861165390","4690526999091256758990293462794369238","7544939645273274879206324847218671046","12071255814901493088040976794853679443","164998211426005178073519557115678279380","224677706242864877018902563102024141642","33215650706164921697314748434731617263","123209350887477386788433845434072400276","9931110887952007559812108128041600154","214728215846428908470951434899761443372","278832171060732843206969616038814260467"]},"target":{"file":"src/com/android/providers/telephony/MmsProvider.java"},"signature_version":"v1"}],"severity":"High","types":["DoS"],"fixes":["https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-264880689.json"}},{"package":{"name":"platform/packages/providers/TelephonyProvider","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13:0"},{"fixed":"13:2023-08-01"}]}],"versions":["13"],"ecosystem_specific":{"spl":"2023-08-01","vanir_signatures":[{"id":"ASB-A-264880689-78ae990a","source":"https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c","signature_type":"Line","deprecated":false,"digest":{"threshold":0.9,"line_hashes":["281253907639525144025299373930782407033","132876137314617094737140570055861165390","4690526999091256758990293462794369238","7544939645273274879206324847218671046","12071255814901493088040976794853679443","164998211426005178073519557115678279380","224677706242864877018902563102024141642","33215650706164921697314748434731617263","123209350887477386788433845434072400276","9931110887952007559812108128041600154","214728215846428908470951434899761443372","278832171060732843206969616038814260467"]},"target":{"file":"src/com/android/providers/telephony/MmsProvider.java"},"signature_version":"v1"},{"id":"ASB-A-264880689-fdc3403f","source":"https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c","signature_type":"Function","deprecated":false,"digest":{"function_hash":"157104286834053058667808334963109926916","length":2447},"target":{"file":"src/com/android/providers/telephony/MmsProvider.java","function":"update"},"signature_version":"v1"}],"severity":"High","types":["DoS"],"fixes":["https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6743638a096c32627f398efd2ea78f08b8a2db8c"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-264880689.json"}}],"schema_version":"1.7.5"}