In btahfclienthandlecindlistitem of btahfclient_at.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"length": 562.0,
"function_hash": "99527865329864812908024186541795315569"
},
"id": "ASB-A-224536184-7abd703e",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/01136338f6d739226e027716b6e5304df379fa4c",
"target": {
"function": "bta_hf_client_handle_cind_list_item",
"file": "bta/hf_client/bta_hf_client_at.cc"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"69202097141331435759913898533140182647",
"339856804970668910245066217423079603924",
"338909376581949431436926621779788310255"
]
},
"id": "ASB-A-224536184-8a7e33e5",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/01136338f6d739226e027716b6e5304df379fa4c",
"target": {
"file": "bta/hf_client/bta_hf_client_at.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/01136338f6d739226e027716b6e5304df379fa4c"
],
"types": [
"RCE"
],
"spl": "2022-07-01",
"severity": "Critical"
}
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"69202097141331435759913898533140182647",
"339856804970668910245066217423079603924",
"338909376581949431436926621779788310255"
]
},
"id": "ASB-A-224536184-12123725",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/ea2815973590018a6df5a3e88fa582eb4c8ff04e",
"target": {
"file": "bta/hf_client/bta_hf_client_at.cc"
}
},
{
"digest": {
"length": 562.0,
"function_hash": "99527865329864812908024186541795315569"
},
"id": "ASB-A-224536184-f17b3721",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/ea2815973590018a6df5a3e88fa582eb4c8ff04e",
"target": {
"function": "bta_hf_client_handle_cind_list_item",
"file": "bta/hf_client/bta_hf_client_at.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/ea2815973590018a6df5a3e88fa582eb4c8ff04e"
],
"types": [
"RCE"
],
"spl": "2022-07-01",
"severity": "Critical"
}
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"69202097141331435759913898533140182647",
"339856804970668910245066217423079603924",
"338909376581949431436926621779788310255"
]
},
"id": "ASB-A-224536184-71dd4a58",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/6d092ae08e8bcd7cacd50d52e1139b9d59239c87",
"target": {
"file": "bta/hf_client/bta_hf_client_at.cc"
}
},
{
"digest": {
"length": 562.0,
"function_hash": "99527865329864812908024186541795315569"
},
"id": "ASB-A-224536184-f2731194",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/6d092ae08e8bcd7cacd50d52e1139b9d59239c87",
"target": {
"function": "bta_hf_client_handle_cind_list_item",
"file": "bta/hf_client/bta_hf_client_at.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/6d092ae08e8bcd7cacd50d52e1139b9d59239c87"
],
"types": [
"RCE"
],
"spl": "2022-07-01",
"severity": "Critical"
}