{"id":"ASB-A-190286685", "published":"2021-11-01T00:00:00Z", "modified":"2026-05-01T15:24:27.653932157Z", "aliases":["CVE-2021-0650", "A-190286685"], "details":"In WT_InterpolateNoLoop of eas_wtengine.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.", "affected":[{"package":{"name":"platform/external/sonivox", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"9:0"}, {"fixed":"9:2021-11-01"}]}], "versions":["9"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/external/sonivox/+/8bfcd9c03af5170b5003712fb77f096b5c9f341b"], "severity":"High", "spl":"2021-11-01", "types":["ID"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["72310663230475707915647199668845906824", "139679271753726367591557254958294601188", "298033914956701449834459594892389982814", "217668571837934243891402720260636482954", "18502597508148223644531323600690056264", "14593401514144437976699628558059293216", "165442401316347328660392367378029319580", "235243037835305535519076035220725703283", "35222342050603053417411412432547385839", "339071380161650865093924943462963586879", "103751839871934057808063796404643818331", "101131050099693957166445146746675700465", "39889290398108461417778246792892668655", "259234348619225104787879816085938629572", "231361967036040571724966677528908519580", "275059295861124206757671160939923787269", "214595645295990633473556637685062717452", "10821762503205520951248569938463697741", "198025968175308871864996960896913130623"], "threshold":0.9}, "id":"ASB-A-190286685-87961578", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/external/sonivox/+/8bfcd9c03af5170b5003712fb77f096b5c9f341b", "target":{"file":"arm-wt-22k/lib_src/eas_wtengine.c"}}, {"deprecated":false, "digest":{"function_hash":"235663036639182444856967758127903166780", "length":1015}, "id":"ASB-A-190286685-be73b5fe", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/external/sonivox/+/8bfcd9c03af5170b5003712fb77f096b5c9f341b", "target":{"file":"arm-wt-22k/lib_src/eas_wtengine.c", "function":"WT_InterpolateNoLoop"}}]}}, {"package":{"name":"platform/external/sonivox", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"10:0"}, {"fixed":"10:2021-11-01"}]}], "versions":["10"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/external/sonivox/+/8bfcd9c03af5170b5003712fb77f096b5c9f341b"], "severity":"High", "spl":"2021-11-01", "types":["ID"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["72310663230475707915647199668845906824", "139679271753726367591557254958294601188", "298033914956701449834459594892389982814", "217668571837934243891402720260636482954", "18502597508148223644531323600690056264", "14593401514144437976699628558059293216", "165442401316347328660392367378029319580", "235243037835305535519076035220725703283", "35222342050603053417411412432547385839", "339071380161650865093924943462963586879", "103751839871934057808063796404643818331", "101131050099693957166445146746675700465", "39889290398108461417778246792892668655", "259234348619225104787879816085938629572", "231361967036040571724966677528908519580", "275059295861124206757671160939923787269", "214595645295990633473556637685062717452", "10821762503205520951248569938463697741", "198025968175308871864996960896913130623"], "threshold":0.9}, "id":"ASB-A-190286685-84159f65", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/external/sonivox/+/8bfcd9c03af5170b5003712fb77f096b5c9f341b", "target":{"file":"arm-wt-22k/lib_src/eas_wtengine.c"}}, {"deprecated":false, "digest":{"function_hash":"235663036639182444856967758127903166780", "length":1015}, "id":"ASB-A-190286685-bbb2caa4", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/external/sonivox/+/8bfcd9c03af5170b5003712fb77f096b5c9f341b", "target":{"file":"arm-wt-22k/lib_src/eas_wtengine.c", "function":"WT_InterpolateNoLoop"}}]}}, {"package":{"name":"platform/external/sonivox", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"11:0"}, {"fixed":"11:2021-11-01"}]}], "versions":["11"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/external/sonivox/+/8bfcd9c03af5170b5003712fb77f096b5c9f341b"], "severity":"High", "spl":"2021-11-01", "types":["ID"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["72310663230475707915647199668845906824", "139679271753726367591557254958294601188", "298033914956701449834459594892389982814", "217668571837934243891402720260636482954", "18502597508148223644531323600690056264", "14593401514144437976699628558059293216", "165442401316347328660392367378029319580", "235243037835305535519076035220725703283", "35222342050603053417411412432547385839", "339071380161650865093924943462963586879", "103751839871934057808063796404643818331", "101131050099693957166445146746675700465", "39889290398108461417778246792892668655", "259234348619225104787879816085938629572", "231361967036040571724966677528908519580", "275059295861124206757671160939923787269", "214595645295990633473556637685062717452", "10821762503205520951248569938463697741", "198025968175308871864996960896913130623"], "threshold":0.9}, "id":"ASB-A-190286685-f809cb86", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/external/sonivox/+/8bfcd9c03af5170b5003712fb77f096b5c9f341b", "target":{"file":"arm-wt-22k/lib_src/eas_wtengine.c"}}, {"deprecated":false, "digest":{"function_hash":"235663036639182444856967758127903166780", "length":1015}, "id":"ASB-A-190286685-faab01eb", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/external/sonivox/+/8bfcd9c03af5170b5003712fb77f096b5c9f341b", "target":{"file":"arm-wt-22k/lib_src/eas_wtengine.c", "function":"WT_InterpolateNoLoop"}}]}}], "references":[{"type":"ADVISORY", "url":"https://source.android.com/security/bulletin/2021-11-01"}, {"type":"FIX", "url":"https://android.googlesource.com/platform/external/sonivox/+/8bfcd9c03af5170b5003712fb77f096b5c9f341b"}]}