ZeroHour
oss-securitypublished ()ingested 1

Memory-safety defects in the upstream (abandoned) AOSP OpenCORE AAC decoder, shipped unpatched by Samsung TizenRT

mediumVulnerabilityimportance 40
AI summary · glm-5.3-flash

Abandoned AOSP OpenCORE AAC decoder has out-of-bounds-write and wild-pointer flaws reachable from attacker-controlled frames, unpatched in Samsung TizenRT.

The OpenCORE AAC decoder in AOSP's abandoned external/opencore tree contains memory-safety defects of the out-of-bounds-write and wild-pointer class. The code is still vendored and built by multiple projects, most notably Samsung's widely deployed TizenRT embedded RTOS. The defects are reachable from untrusted media because an AAC frame is attacker-controlled. The researcher is requesting a CVE ID for the issue.

  • Out-of-bounds-write and wild-pointer defects found in the AOSP OpenCORE AAC decoder.
  • Attacker-controlled AAC frames can trigger the memory-safety bugs.
  • Samsung TizenRT still vendors the abandoned, unpatched decoder.
  • CVE ID requested; the upstream component is abandoned.
Full article

Posted by Eve on Sep 09 Summary ======= The OpenCORE AAC decoder (AOSP external/opencore, codecs_v2/audio/aac/dec) is abandoned upstream but is still vendored and built by multiple projects, most notably Samsung's TizenRT (a widely-deployed embedded RTOS). It contains memory-safety defects of the out-of-bounds-write and wild-pointer class, reachable from untrusted media (an AAC frame is attacker-controlled). I request a CVE ID for this issue. What I executed vs....

This source does not provide full text. Read it at seclists.org.