android-security-16.0.0_r7 to android-security-16.0.0_r8 AOSP changelog

This only includes the Android Open Source Project changes and does not include any changes in any proprietary components included by Google or any hardware manufacturer. The raw log was generated using a modified version of this script written by JBQ and improved by Al Sutton.

Please do not copy this without attribution to this site and JBQ for the original script.

+- Project: platform/art

a57f914df7 : Make the runtime-generated app image read-only

+- Project: platform/bionic

50cbdffd6 : Fix bad free when limit exceeded.

+- Project: platform/build

f96640a9df : Version bump to BP2A.250805.043 [core/build_id.mk] 1171a7429b : Version bump to BP2A.250805.042 [core/build_id.mk] a13368fa36 : Version bump to BP2A.250805.041 [core/build_id.mk] a3a3c064f7 : Version bump to BP2A.250805.040 [core/build_id.mk] dffcffbf37 : Version bump to BP2A.250805.039 [core/build_id.mk] f3113e55f9 : Version bump to BP2A.250805.038 [core/build_id.mk] 5de9b345d8 : Version bump to BP2A.250805.037 [core/build_id.mk] 6fa6355fea : Version bump to BP2A.250805.036 [core/build_id.mk] dbfd21a214 : Version bump to BP2A.250805.035 [core/build_id.mk]

+- Project: platform/development

8b9e6db92c : Fix potential NPEs in PduParser.parsePartHeaders

+- Project: platform/external/dng_sdk

c4ffcdb : Update to DNG SDK 1.7.1 2502

+- Project: platform/external/exfatprogs

c0e2d5c : ANDROID: Fix fsck overflows when handling bad clu_count or vol_length fields. 9b79c19 : ANDROID: Add support for building exfat tests.

+- Project: platform/external/freetype

6ca3925a3 : Fix heap underflow write in ft_smooth_raster_lcd 6770ef4d9 : * src/sfnt/ttcolr.c (tt_face_colr_blend_layer): Use FT_ALLOC_MULT. 285b264bf : [ttgxvar] Check for overflow in array size computation.

+- Project: platform/external/libhevc

5492b02 : libhevcdec: Fix heap buffer overflow in ihevcd_get_tu_data_size

+- Project: platform/external/libopenapv

b40bceb : [libopenapv] Add dimension validation in dec_frm_prepare

+- Project: platform/external/libpng

0b9147198 : fix(arm): Resolve out-of-bounds read/write in NEON palette expansion

+- Project: platform/external/wpa_supplicant_8

65799238 : wpa_supplicant: Fix OOB read in get_eht_op_width d1315403 : Fix heap OOB write in Robust AV SCS Response handler b812bef9 : Fix NAN frequency list handling in AIDL interfaces. 3f792f7b : Fix P2P2 PBMA Cookie Heap Overflow and harden wpa_supplicant/hostapd

+- Project: platform/frameworks/av

0031ce0a88 : Fix race conditions in CryptoHal plugin usage 183c2e3a41 : Fix type confusion in mediatuner service aff9120ec0 : Camera: Fix heap OOB read/write in camera mappers 6e240fe406 : DeprecatedCamera3StreamSplitter: Add bounds check for slot index ccc6327411 : Fix MediaBuffer size-inflation off-by-32 bug 2cd4f2d9a1 : Fix OOB in DynamicsProcessing MBC band processing 9456667afa : Fix signed overflow in convertCleanApertureToRect 6ff99fe0d5 : [media] Fix heap-buffer-overflow in AudioAttributes unmarshalling f3bd2850ba : [media] Fix heap out-of-bounds write in MatroskaSource::read

+- Project: platform/frameworks/base

3184e06e737a : Fix silence-injection policy skip in VirtualAudioController a5fd26078dba : [25Q2] Mitigate BAL bypass via Companion Device Manager 9444f519c4e5 : Fix a regression in ECM mode setting after package install f4e7001b21fb : Fix boot-loop vulnerability in setPermissionGrantState e8ef27e17d89 : Sanitize labels in GrantCredentialsPermissionActivity 74f5e6fa6a20 : aapt2: Sanitize Javadoc comments to prevent code injection 01f51483eb2f : Fix potential NPEs in PduParser.parsePartHeaders a28fb127a57b : RESTRICT AUTOMERGE: Fix vulnerabilities in PduParser 01bff648b538 : ResStringPool: Validate styleCount and offsets a0bd9f4b3d53 : Truncate long device admin descriptions 431c43bd57cc : Limit knownActivityEmbeddingCerts in manifest c47530a0f8f4 : Use byte count rather than string length for NMS component name check e5560bd1d0c2 : SystemUi UsbDialog: fix label vulnerability 35058d93a551 : Fix path traversal and missing ownership check in LocaleManagerService b159c903dc1d : Add Task-level input sink to block cross-task tap pass-through 8c6681692185 : Move input sink on top of the Activity when needed 0209580ab87a : Check notification permission in getAuthToken(notifyOnAuthFailure). cf0b6cd90ce0 : Add size validation and trimming for ShortcutInfo objects. 2e7f56e02d86 : Hide media on smartspace view when setting is disabled 84d85dbe121f : RESTRICT AUTOMERGE Fix security vulnerability in getManageSpaceActivityIntent 63f908ebd9ee : Validate caller UID in openProxyFileDescriptor 91cf2b3195ed : Add bracket checking support to SQLiteTokenizer 794ac2765d10 : [LocalImageResolver] Fix security check bypass 05c5903d27b8 : Fix BAL bypass via getAppMarketActivityIntent 3d614f9e98a3 : LauncherApps: Scrub sensitive URIs in install sessions fb6a81e33d54 : Autofill SaveUi URL validation and FLAG_IMMUTABLE 6fe346abe6fb : Remove usage of Parcel.allowSquashing in RemoteViews and immediate unparceling of Bundle 0e9656e2222e : Revert^2 "Writing ApplicationInfoCache instead of multiple ApplicationInfos for nested RemoteViews" b61562e1abe6 : Fix using the base type for checking 8c2ce8c567a2 : Properly parse meta_key in AccountsDb. cabd39ad7bd1 : Security bug fix: Prevent USB data changes for non-owner users during lockdown mode. e95170c6378e : Harden startNextMatchingActivity() caller identity propagation. a660d0c46482 : Don't parse 3p recognizer metadata in safe mode 2f86ea93fcdd : Fix FGS mode in test dba6ec2c05ff : Validate caller in SlicePermissionActivity to prevent spoofing. 353a1fa497d3 : Update URI permission granting logic in Intent Redirection Hardening 5e717959bef1 : Restrict VirtualDeviceImpl methods to device owner. 7d8be5eb6753 : Sanitize intent selector in IntentForwarderActivity 71d6dc109528 : Fix & speed up IntentForwarderActivityTest f2a29f4351f8 : RESTRICT AUTOMERGE [ExternalStorageProvider] Revoke URI permissions by path c9290fc206ca : Use setHideOverlayWindows instead of AppOpsManager 80b1b1fe63b5 : DO NOT MERGE: [ClipboardService] Check notification setting for given user 581fd9950f41 : Catch OutOfMemoryError while parsing xml in GameManagerService 585e7556fcec : Fix URI grant persistence bypass f7398bb64526 : Move intent redirect checks before intent resolution. 5108d2606324 : Fix intent redirect bypass via selector in addCreatorToken 8785e148ca82 : RESTRICT AUTOMERGE Filter ignorable Unicode codepoints in ExternalStorageProvider bc676d257ca0 : Fix entryadapter usage 98be98fe443d : Make destAddr nullable de08a320e58b : Set hide overlays on mini resolver 2b8a07bf7437 : Disallow launch-behind animation if BAL blocks 2e158f2d9a81 : Refactor: Add permission checks to Unarchive activities

+- Project: platform/frameworks/opt/telephony

cdc2bb3686 : Fix ArrayIndexOutOfBoundsException in SIMRecords due to invalid EF_CFIS/EF_CFF ee04a37583 : Block in-call MMI execution for USSD requests. b77a21c161 : Add subscription-user association check.

+- Project: platform/hardware/interfaces

0b6f21543e : AIDL CAS HAL: Fix incorrect mmap failure check

+- Project: platform/hardware/nxp/nfc

8e5737ab : Fix Use-After-Free in NXP NFC HAL timer teardown

+- Project: platform/hardware/nxp/secure_element

466c2e7 : Fix out-of-bounds write in SecureElement openLogicalChannel

+- Project: platform/packages/apps/Car/Settings

1075d04ab9 : Replace DeviceAdminInfo.loadDescription() with loadDescriptionSafe() 7f7505117e : Check getLaunchedFromPackage for CE Storage 770d737414 : Fix DeviceAdminAddHeaderPreferenceControllerTest 6ee22d7bc3 : Use setHideOverlayWindows instead of AppOpsManager

+- Project: platform/packages/apps/ManagedProvisioning

13d3d6653 : Prevent Setup Wizard from starting provisioning if the device is already provisioned.

+- Project: platform/packages/apps/Settings

d125be8375f : Replace DeviceAdminInfo.loadDescription() with loadDescriptionSafe() 23e5e4077bc : Sanitize sensitive BiometricsSettingsBase extra afbec373ef1 : Fix confused deputy in Bluetooth settings dashboard 5db0f9425d8 : Sanitize package labels in SettingsApplication 03d4a5b7343 : [Settings] Avoid start wrong fragment from MobileNetworkActivity 192ccfdcab3 : Remove EXTRA_DATA from ConfirmDeviceCredentialActivity 3bf7abe6e14 : [Settings] Strip URI grant flags in AppRestrictionsFragment f6b6ecb4b6e : Use setHideOverlayWindows instead of AppOpsManager bf85ca6c87f : Remove dialog building logic from PaymentDefaultDialog onCreate. 3ee7e15a126 : [RESTRICT AUTOMERGE] Ensure remote device credential alias is used for action CONFIRM_REMOTE_DEVICE_CREDENTIAL.

+- Project: platform/packages/apps/TV

86fb1060 : [LiveTv] Avoid Intent Redirection to permission protected Activities 856a260c : [LiveTv] Fix Intent redirection issue in SetupPassthroughActivity d688b272 : [LiveTV] Specify intent package for "Send Feedback"

+- Project: platform/packages/apps/TvSettings

4760b7d12a : Use loadDescriptionSafe for DeviceAdmin descriptions. 71c0d7a996 : Use setHideOverlayWindows instead of AppOpsManager

+- Project: platform/packages/modules/Bluetooth

91bef351ef6 : Fix buffer overflow in UUID parsing cec4b7bfe86 : GATT: Fix notifications sent to remote device without security checks 6effdf3d7c1 : Fix out-of-bounds heap write in SnoopLogger fec825e4855 : Fix cross-thread UAF in AvrcpService updates 3d959c92292 : Fix uninitialized pointer dereference in MsftExtensionManager 947e8bbe7dc : [RESTRICT AUTOMERGE] Fix SDP server heap buffer overflow a74f9439828 : [RESTRICT AUTOMERGE] Enforce incoming CTKD security requirements 5eefb7cb0b0 : [RESTRICT AUTOMERGE] Fix heap buffer overflow in A2DP Opus decoder 07542331e7c : Remove bond caller info when bonding concludes 8b61335e498 : Reject unsafe LE encryption key sizes 23f057ce56f : Handle concurrency issues in SDP record creation

+- Project: platform/packages/modules/IntentResolver

661c048f : Sanitize alternate intents. 0b02866f : Sanitize intent selector in IntentForwarderActivity

+- Project: platform/packages/modules/Nfc

0779a96c2 : Fix integer underflow and OOB access in libnfc-nci 38cc06501 : Fix integer underflow in rw_ci_data_cback d6cb6aefb : Fix out-of-bounds write in NFC activation handling 3cfc747e2 : Fix heap buffer overflow in nfa_t4tnfcee_store_rx_buf b79e5fd8c : Fix OOB write in rw_mfc_handle_read_op 92d884176 : Fix potential integer overflow in Type 3 Tag block operations. 2db7814d8 : Prevent buffer overflow on oversized HAL packets 4f214cca6 : Fix Heap OOBW in nfa_t4tnfcee_store_rx_buf() 9c0ae67d8 : Fix bounds check underflow and GKI buffer leak in T4T write 144b34ba8 : Prevent information disclosure over RF in rw_t5t.cc 4648c160b : Fix uint16 loop counter wrap in T3T NDEF CHECK/UPDATE ca73224fb : Terminate MFC NDEF read on length inflation attempt 6bc72fe8b : Force unbind service on binding died ebbca6f81 : [NFC flag] Clean up aconfig flag check_passed_in_package

+- Project: platform/packages/modules/Uwb

618d9adfc : Enforce ranging permission for OOB ranging APIs. 4a9740318 : [GRAPI] Mask Mac Address in BleRangingCapabilities

+- Project: platform/packages/modules/Wifi

4d8225a6d0 : Fix persistent DoS in WifiNetworkSuggestionsManager via PersistableBundle depth bomb

+- Project: platform/packages/modules/adb

f487f473 : [adb] Fix Use-After-Free in TLS handshake. 1c97946b : [adb] Document and harden async transport flow.

+- Project: platform/packages/providers/ContactsProvider

7a3c86a5 : Restrict max size for Note.NOTE field 3c11261b : Prevent SQL injection in SelectionBuilder

+- Project: platform/packages/providers/DownloadProvider

a3ba6b22 : RESTRICT AUTOMERGE Fix ZWSP path bypass in DownloadProvider e28ef02f : RESTRICT AUTOMERGE Fix DownloadProvider completed download security bypass 2d651e87 : RESTRICT AUTOMERGE Fix path traversal vulnerability in DownloadStorageProvider 21361e1d : RESTRICT AUTOMERGE Revoke URI permissions for specific document paths

+- Project: platform/packages/providers/MediaProvider

f108d16cda : RESTRICT AUTOMERGE Use parameterised queries for photo picker search request queries cedfc5086b : RESTRICT AUTOMERGE Fix location redaction bypass for oversized XMP boxes. 32217e55e5 : RESTRICT AUTOMERGE Improve preselcted media URI validation 94374dc411 : RESTRICT AUTOMERGE Fix MediaStore race condition for pending files 4d92f79329 : RESTRICT AUTOMERGE Revoke URI permissions on file path updates 4bdbc2fa9f : RESTRICT AUTOMERGE Fix ISO XMP location redaction bypass

+- Project: platform/packages/providers/TelephonyProvider

a8c60526 : TelephonyProvider: Fix SQL injection in projection and sortOrder 190c0a3b : Filter MMS/SMS queries by subscription ID

+- Project: platform/packages/services/BuiltInPrintService

883f3a18 : Limit media-supported values

+- Project: platform/packages/services/Telecomm

c36565c870 : Fix MMI check bypass via leading whitespace in tel URI. 3d2e80ac19 : Update fix for initiating calls from work profile 125c1454cb : Check caller in CSW#queryRemoteConnectionServices a87be58dc7 : Resolve cross account user ringtone validation.

+- Project: platform/packages/services/Telephony

3cf52f33f1 : Fix StackOverflowError in SatelliteEntitlementController 73bc9bf6eb : [Telephony] Secure contact URI access in Call Forwarding 03cc6ee760 : Restrict USSD requests to the subscription's associated user. d394116062 : Prevent SDK Sandbox from bypassing isSystemApp check

+- Project: platform/system/incremental_delivery

67b14f0 : [incfs] Reduce the stack buffer size for pread()

+- Project: platform/system/libfmq

3aa82fe : Reapply "Handle corrupted read/write pointers in read funcitons"

+- Project: platform/system/libufdt

8dfd47a : libufdt: Fix stack overflow risk in vendor qsort

+- Project: platform/system/media

312249da : Fix camera metadata entry capacity validation.