In sdpcopyrawdata of sdpdiscovery.cc, there is a possible system compromise due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"length": 1567.0,
"function_hash": "226686015420630971083399221244405337653"
},
"id": "ASB-A-174052148-355c0420",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/f0994f6e4723eddaa617b68139f064d945d9389e",
"target": {
"function": "bta_ag_do_disc",
"file": "bta/ag/bta_ag_sdp.cc"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"217178944041883988427998995336572607779",
"268620471652406614036610575577336396100",
"195065986137907670458925705109645393804",
"316120188592456273022294446303766069277",
"196166543744440592454744695116625660291",
"296185697512847952591049413753396635607",
"78880808084593515505501064767592671743"
]
},
"id": "ASB-A-174052148-67c43063",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/f0994f6e4723eddaa617b68139f064d945d9389e",
"target": {
"file": "bta/ag/bta_ag_sdp.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/f0994f6e4723eddaa617b68139f064d945d9389e"
],
"types": [
"RCE"
],
"spl": "2021-03-01",
"severity": "Critical"
}
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"217178944041883988427998995336572607779",
"268620471652406614036610575577336396100",
"195065986137907670458925705109645393804",
"316120188592456273022294446303766069277",
"196166543744440592454744695116625660291",
"296185697512847952591049413753396635607",
"78880808084593515505501064767592671743"
]
},
"id": "ASB-A-174052148-09d29643",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/f0994f6e4723eddaa617b68139f064d945d9389e",
"target": {
"file": "bta/ag/bta_ag_sdp.cc"
}
},
{
"digest": {
"length": 1567.0,
"function_hash": "226686015420630971083399221244405337653"
},
"id": "ASB-A-174052148-cdbb04e8",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/f0994f6e4723eddaa617b68139f064d945d9389e",
"target": {
"function": "bta_ag_do_disc",
"file": "bta/ag/bta_ag_sdp.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/f0994f6e4723eddaa617b68139f064d945d9389e"
],
"types": [
"RCE"
],
"spl": "2021-03-01",
"severity": "Critical"
}
{
"vanir_signatures": [
{
"digest": {
"length": 1567.0,
"function_hash": "226686015420630971083399221244405337653"
},
"id": "ASB-A-174052148-0f6751e5",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/f0994f6e4723eddaa617b68139f064d945d9389e",
"target": {
"function": "bta_ag_do_disc",
"file": "bta/ag/bta_ag_sdp.cc"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"217178944041883988427998995336572607779",
"268620471652406614036610575577336396100",
"195065986137907670458925705109645393804",
"316120188592456273022294446303766069277",
"196166543744440592454744695116625660291",
"296185697512847952591049413753396635607",
"78880808084593515505501064767592671743"
]
},
"id": "ASB-A-174052148-682c0a64",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/f0994f6e4723eddaa617b68139f064d945d9389e",
"target": {
"file": "bta/ag/bta_ag_sdp.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/f0994f6e4723eddaa617b68139f064d945d9389e"
],
"types": [
"RCE"
],
"spl": "2021-03-01",
"severity": "Critical"
}
{
"vanir_signatures": [
{
"digest": {
"length": 1567.0,
"function_hash": "226686015420630971083399221244405337653"
},
"id": "ASB-A-174052148-5850ecb8",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/f0994f6e4723eddaa617b68139f064d945d9389e",
"target": {
"function": "bta_ag_do_disc",
"file": "bta/ag/bta_ag_sdp.cc"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"217178944041883988427998995336572607779",
"268620471652406614036610575577336396100",
"195065986137907670458925705109645393804",
"316120188592456273022294446303766069277",
"196166543744440592454744695116625660291",
"296185697512847952591049413753396635607",
"78880808084593515505501064767592671743"
]
},
"id": "ASB-A-174052148-5f778341",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/f0994f6e4723eddaa617b68139f064d945d9389e",
"target": {
"file": "bta/ag/bta_ag_sdp.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/f0994f6e4723eddaa617b68139f064d945d9389e"
],
"types": [
"RCE"
],
"spl": "2021-03-01",
"severity": "Critical"
}