The servicemanager, keystore and drmserver all use getpidcon function to get the security context of the caller from a binder. When combined with a one way binder transaction this results in getting the security context of the current process which might allow a selinux mac bypass.
2490431986cf0e3ac461ee3404bc3e4c47f1124ec963ad8e900b6344954fe156