{"id":"ASB-A-269270167","details":"In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-269270167","CVE-2023-35664"],"modified":"2026-05-22T15:55:21.353668239Z","published":"2023-09-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2023-09-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/packages/modules/NeuralNetworks/+/47299fd978258e67a8eebc361cb7a4dd2936205e"}],"affected":[{"package":{"name":"platform/packages/modules/NeuralNetworks","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13-next:0"},{"fixed":"13-next:2023-09-01"}]}],"versions":["13-next"],"ecosystem_specific":{"severity":"High","types":["ID"],"spl":"2023-09-01","vanir_signatures":[{"digest":{"threshold":0.9,"line_hashes":["87946936132308608384478622008411577909","305193397338573633694575358239379866069","293244330107898378830319066422829728152","238497066142682013770992329966452972159"]},"id":"ASB-A-269270167-82492551","target":{"file":"shim_and_sl/ShimConverter.cpp"},"deprecated":false,"source":"https://android.googlesource.com/platform/packages/modules/NeuralNetworks/+/4bf7bb6b50b412678a681d29f7ced70a4d737762","signature_type":"Line","signature_version":"v1"}],"fixes":["https://android.googlesource.com/platform/packages/modules/NeuralNetworks/+/4bf7bb6b50b412678a681d29f7ced70a4d737762"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-269270167.json"}},{"package":{"name":"platform/packages/modules/NeuralNetworks","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12:0"},{"fixed":"12:2023-09-01"}]}],"versions":["12"],"ecosystem_specific":{"severity":"High","types":["ID"],"spl":"2023-09-01","vanir_signatures":[{"digest":{"threshold":0.9,"line_hashes":["87946936132308608384478622008411577909","305193397338573633694575358239379866069","293244330107898378830319066422829728152","238497066142682013770992329966452972159"]},"id":"ASB-A-269270167-69d1db2d","target":{"file":"shim_and_sl/ShimConverter.cpp"},"deprecated":false,"source":"https://android.googlesource.com/platform/packages/modules/NeuralNetworks/+/6e1bbe89e08936a1cad152a59ae82a3773c51cca","signature_type":"Line","signature_version":"v1"}],"fixes":["https://android.googlesource.com/platform/packages/modules/NeuralNetworks/+/6e1bbe89e08936a1cad152a59ae82a3773c51cca"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-269270167.json"}},{"package":{"name":"platform/packages/modules/NeuralNetworks","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12L:0"},{"fixed":"12L:2023-09-01"}]}],"versions":["12L"],"ecosystem_specific":{"severity":"High","types":["ID"],"spl":"2023-09-01","vanir_signatures":[{"digest":{"threshold":0.9,"line_hashes":["87946936132308608384478622008411577909","305193397338573633694575358239379866069","293244330107898378830319066422829728152","238497066142682013770992329966452972159"]},"id":"ASB-A-269270167-84bd284b","target":{"file":"shim_and_sl/ShimConverter.cpp"},"deprecated":false,"source":"https://android.googlesource.com/platform/packages/modules/NeuralNetworks/+/e6e1ad6669075ccb70fc27eb67905d76993ed422","signature_type":"Line","signature_version":"v1"}],"fixes":["https://android.googlesource.com/platform/packages/modules/NeuralNetworks/+/e6e1ad6669075ccb70fc27eb67905d76993ed422"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-269270167.json"}},{"package":{"name":"platform/packages/modules/NeuralNetworks","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13:0"},{"fixed":"13:2023-09-01"}]}],"versions":["13"],"ecosystem_specific":{"vanir_signatures":[{"digest":{"threshold":0.9,"line_hashes":["87946936132308608384478622008411577909","305193397338573633694575358239379866069","293244330107898378830319066422829728152","238497066142682013770992329966452972159"]},"id":"ASB-A-269270167-9ee25742","target":{"file":"shim_and_sl/ShimConverter.cpp"},"deprecated":false,"source":"https://android.googlesource.com/platform/packages/modules/NeuralNetworks/+/244ac21307a785d49930d4c7e289b74856fa9647","signature_type":"Line","signature_version":"v1"}],"types":["ID"],"spl":"2023-09-01","severity":"High","fixes":["https://android.googlesource.com/platform/packages/modules/NeuralNetworks/+/244ac21307a785d49930d4c7e289b74856fa9647"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-269270167.json"}}],"schema_version":"1.7.5"}