Edwin Wong 9fcd4886a3 [RESTRICT AUTOMERGE] Fix CryptoPlugin use after free vulnerability.
The shared memory buffer used by srcPtr can be freed by another
thread because it is not protected by a mutex. Subsequently,
a use after free AIGABRT can occur in a race condition.

SafetyNet logging is not added to avoid log spamming. The
mutex lock is called to setup for decryption, which is
called frequently.

The crash was reproduced on the device before the fix.
Verified the test passes after the fix.

Test: sts
  sts-tradefed run sts-engbuild-no-spl-lock -m StsHostTestCases --test android.security.sts.Bug_176495665#testPocBug_176495665

Test: push to device with target_hwasan-userdebug build
  adb shell /data/local/tmp/Bug-176495665_sts64

Bug: 176495665
Bug: 176444161
Change-Id: I3ec33cd444183f40ee76bec4c88dec0dac859cd3
2021-03-08 23:27:38 -08:00
2019-03-04 11:27:17 -08:00
2019-03-04 11:27:17 -08:00
2019-03-04 11:27:17 -08:00
2019-03-04 11:27:17 -08:00
2019-03-04 11:27:17 -08:00
2019-06-18 16:09:36 +08:00
2019-03-04 11:27:17 -08:00
2019-03-04 11:27:17 -08:00
2019-03-04 11:27:17 -08:00
2019-02-27 12:22:54 +09:00
2016-08-30 11:28:36 -07:00
2016-08-30 11:28:36 -07:00
2019-02-12 11:25:14 -08:00
Description
No description provided
134 MiB
Languages
C++ 56.3%
AIDL 41.2%
C 1.5%
Rust 0.4%
Java 0.4%
Other 0.1%