{"id":"ASB-A-269271098","details":"In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-269271098","CVE-2023-40085"],"modified":"2026-05-22T15:55:21.353668239Z","published":"2024-01-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2024-01-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/packages/modules/NeuralNetworks/+/ed6ee1f7eca7b33160e36ac6d730a9ef395ca4f1"}],"affected":[{"package":{"name":"platform/packages/modules/NeuralNetworks","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12:0"},{"fixed":"12:2024-01-01"}]}],"versions":["12"],"ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/modules/NeuralNetworks/+/a80b30fff9550baead3ea7f6984053d90236dc9f"],"severity":"High","types":["ID"],"vanir_signatures":[{"id":"ASB-A-269271098-10ccd010","target":{"file":"shim_and_sl/ShimConverter.cpp"},"source":"https://android.googlesource.com/platform/packages/modules/NeuralNetworks/+/a80b30fff9550baead3ea7f6984053d90236dc9f","signature_version":"v1","digest":{"threshold":0.9,"line_hashes":["89365170970992669584656027371400731194","53532013549472810034455140374389154140","147733096384270577092978024019724627330","2778514037793002499354008786167043654"]},"deprecated":false,"signature_type":"Line"}],"spl":"2024-01-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-269271098.json"}},{"package":{"name":"platform/packages/modules/NeuralNetworks","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12L:0"},{"fixed":"12L:2024-01-01"}]}],"versions":["12L"],"ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/modules/NeuralNetworks/+/22a20c01cc01dbb36ecbc68e664a070c4ffad2cf"],"severity":"High","types":["ID"],"vanir_signatures":[{"id":"ASB-A-269271098-ce738a08","target":{"file":"shim_and_sl/ShimConverter.cpp"},"source":"https://android.googlesource.com/platform/packages/modules/NeuralNetworks/+/22a20c01cc01dbb36ecbc68e664a070c4ffad2cf","signature_version":"v1","digest":{"threshold":0.9,"line_hashes":["89365170970992669584656027371400731194","53532013549472810034455140374389154140","147733096384270577092978024019724627330","2778514037793002499354008786167043654"]},"deprecated":false,"signature_type":"Line"}],"spl":"2024-01-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-269271098.json"}},{"package":{"name":"platform/packages/modules/NeuralNetworks","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13:0"},{"fixed":"13:2024-01-01"}]}],"versions":["13"],"ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/modules/NeuralNetworks/+/22a20c01cc01dbb36ecbc68e664a070c4ffad2cf"],"severity":"High","types":["ID"],"vanir_signatures":[{"id":"ASB-A-269271098-f9a3876e","signature_type":"Line","source":"https://android.googlesource.com/platform/packages/modules/NeuralNetworks/+/22a20c01cc01dbb36ecbc68e664a070c4ffad2cf","signature_version":"v1","digest":{"threshold":0.9,"line_hashes":["89365170970992669584656027371400731194","53532013549472810034455140374389154140","147733096384270577092978024019724627330","2778514037793002499354008786167043654"]},"deprecated":false,"target":{"file":"shim_and_sl/ShimConverter.cpp"}}],"spl":"2024-01-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-269271098.json"}}],"schema_version":"1.7.5"}