In processservicesearchrsp of sdpdiscovery.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"length": 1357.0,
"function_hash": "214677880682482865561700894288717992832"
},
"id": "ASB-A-225876506-6b125250",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/18d69eb958493d4879786e2edb42ff4e60334a2f",
"target": {
"function": "process_service_search_rsp",
"file": "stack/sdp/sdp_discovery.cc"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"110629173430261047634653274356077522246",
"3086676120985718028309252445904192238",
"45515098642018986227259658136777715096",
"166089682084964583941119191231270104935"
]
},
"id": "ASB-A-225876506-b43c1db5",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/18d69eb958493d4879786e2edb42ff4e60334a2f",
"target": {
"file": "stack/sdp/sdp_discovery.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/18d69eb958493d4879786e2edb42ff4e60334a2f"
],
"types": [
"ID"
],
"spl": "2022-11-01",
"severity": "High"
}
{
"vanir_signatures": [
{
"digest": {
"length": 1357.0,
"function_hash": "214677880682482865561700894288717992832"
},
"id": "ASB-A-225876506-b7017dd7",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/864460a945fe47b417def4017fb3d791e829753c",
"target": {
"function": "process_service_search_rsp",
"file": "stack/sdp/sdp_discovery.cc"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"110629173430261047634653274356077522246",
"3086676120985718028309252445904192238",
"45515098642018986227259658136777715096",
"166089682084964583941119191231270104935"
]
},
"id": "ASB-A-225876506-bb79b1cb",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/864460a945fe47b417def4017fb3d791e829753c",
"target": {
"file": "stack/sdp/sdp_discovery.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/864460a945fe47b417def4017fb3d791e829753c"
],
"types": [
"ID"
],
"spl": "2022-11-01",
"severity": "High"
}
{
"vanir_signatures": [
{
"digest": {
"length": 1357.0,
"function_hash": "214677880682482865561700894288717992832"
},
"id": "ASB-A-225876506-6efb37bd",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/eac9616fc32f0bf40d2d2e6d1ff7b453edffc01c",
"target": {
"function": "process_service_search_rsp",
"file": "stack/sdp/sdp_discovery.cc"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"110629173430261047634653274356077522246",
"3086676120985718028309252445904192238",
"45515098642018986227259658136777715096",
"166089682084964583941119191231270104935"
]
},
"id": "ASB-A-225876506-c45fb94c",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/eac9616fc32f0bf40d2d2e6d1ff7b453edffc01c",
"target": {
"file": "stack/sdp/sdp_discovery.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/eac9616fc32f0bf40d2d2e6d1ff7b453edffc01c"
],
"types": [
"ID"
],
"spl": "2022-11-01",
"severity": "High"
}
{
"vanir_signatures": [
{
"digest": {
"length": 1357.0,
"function_hash": "214677880682482865561700894288717992832"
},
"id": "ASB-A-225876506-845d5f6d",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/96f108e8c381e744131dc2f021681b113d6e083b",
"target": {
"function": "process_service_search_rsp",
"file": "system/stack/sdp/sdp_discovery.cc"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"110629173430261047634653274356077522246",
"3086676120985718028309252445904192238",
"45515098642018986227259658136777715096",
"166089682084964583941119191231270104935"
]
},
"id": "ASB-A-225876506-d24a7fde",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/96f108e8c381e744131dc2f021681b113d6e083b",
"target": {
"file": "system/stack/sdp/sdp_discovery.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/96f108e8c381e744131dc2f021681b113d6e083b"
],
"types": [
"ID"
],
"spl": "2022-11-01",
"severity": "High"
}