In smpkeydistribution of smp_act.cc, there are possible vulnerabilities in Cross-Transport Key Derivation due to weaknesses in the Bluetooth standard. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"length": 857.0,
"function_hash": "149862376871960881486779178792629586467"
},
"id": "ASB-A-158854097-bdc605f3",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/775a5e72b34b70ff92d61d8bcc47c6bde663f02e",
"target": {
"function": "smp_key_distribution",
"file": "stack/smp/smp_act.cc"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"141878859893653509495119353880378886755",
"281662226058294302639865591136081592204",
"324547289574088968005916732676261905036",
"90478598410599379139713230843119446223"
]
},
"id": "ASB-A-158854097-cc6c628a",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/775a5e72b34b70ff92d61d8bcc47c6bde663f02e",
"target": {
"file": "stack/smp/smp_act.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/775a5e72b34b70ff92d61d8bcc47c6bde663f02e"
],
"types": [
"ID"
],
"spl": "2020-12-01",
"severity": "High"
}
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"141878859893653509495119353880378886755",
"281662226058294302639865591136081592204",
"324547289574088968005916732676261905036",
"90478598410599379139713230843119446223"
]
},
"id": "ASB-A-158854097-31edadb6",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/775a5e72b34b70ff92d61d8bcc47c6bde663f02e",
"target": {
"file": "stack/smp/smp_act.cc"
}
},
{
"digest": {
"length": 857.0,
"function_hash": "149862376871960881486779178792629586467"
},
"id": "ASB-A-158854097-9b781dab",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/775a5e72b34b70ff92d61d8bcc47c6bde663f02e",
"target": {
"function": "smp_key_distribution",
"file": "stack/smp/smp_act.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/775a5e72b34b70ff92d61d8bcc47c6bde663f02e"
],
"types": [
"ID"
],
"spl": "2020-12-01",
"severity": "High"
}
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"141878859893653509495119353880378886755",
"281662226058294302639865591136081592204",
"324547289574088968005916732676261905036",
"90478598410599379139713230843119446223"
]
},
"id": "ASB-A-158854097-c3fcbe6d",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/775a5e72b34b70ff92d61d8bcc47c6bde663f02e",
"target": {
"file": "stack/smp/smp_act.cc"
}
},
{
"digest": {
"length": 857.0,
"function_hash": "149862376871960881486779178792629586467"
},
"id": "ASB-A-158854097-cdc15383",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/775a5e72b34b70ff92d61d8bcc47c6bde663f02e",
"target": {
"function": "smp_key_distribution",
"file": "stack/smp/smp_act.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/775a5e72b34b70ff92d61d8bcc47c6bde663f02e"
],
"types": [
"ID"
],
"spl": "2020-12-01",
"severity": "High"
}
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"141878859893653509495119353880378886755",
"281662226058294302639865591136081592204",
"324547289574088968005916732676261905036",
"90478598410599379139713230843119446223"
]
},
"id": "ASB-A-158854097-7faeda4b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/775a5e72b34b70ff92d61d8bcc47c6bde663f02e",
"target": {
"file": "stack/smp/smp_act.cc"
}
},
{
"digest": {
"length": 857.0,
"function_hash": "149862376871960881486779178792629586467"
},
"id": "ASB-A-158854097-bba39f70",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/775a5e72b34b70ff92d61d8bcc47c6bde663f02e",
"target": {
"function": "smp_key_distribution",
"file": "stack/smp/smp_act.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/775a5e72b34b70ff92d61d8bcc47c6bde663f02e"
],
"types": [
"ID"
],
"spl": "2020-12-01",
"severity": "High"
}
{
"vanir_signatures": [
{
"digest": {
"length": 857.0,
"function_hash": "149862376871960881486779178792629586467"
},
"id": "ASB-A-158854097-548bddb2",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/775a5e72b34b70ff92d61d8bcc47c6bde663f02e",
"target": {
"function": "smp_key_distribution",
"file": "stack/smp/smp_act.cc"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"141878859893653509495119353880378886755",
"281662226058294302639865591136081592204",
"324547289574088968005916732676261905036",
"90478598410599379139713230843119446223"
]
},
"id": "ASB-A-158854097-fd9686a4",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/775a5e72b34b70ff92d61d8bcc47c6bde663f02e",
"target": {
"file": "stack/smp/smp_act.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/775a5e72b34b70ff92d61d8bcc47c6bde663f02e"
],
"types": [
"ID"
],
"spl": "2020-12-01",
"severity": "High"
}