In BNEPConnectResp of bnepapi.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"19615635629939757925767189986436799647",
"207990587364688167640515750653759914052",
"274620203780754120125403676728619555520",
"32405815071143783313761956769936829827"
]
},
"id": "ASB-A-228450451-38d4fb4b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/0fa54c7d8a2c061202e61d75b805661c1e89a76d",
"target": {
"file": "stack/bnep/bnep_api.cc"
}
},
{
"digest": {
"length": 1562.0,
"function_hash": "251628678351054005449541836964376859324"
},
"id": "ASB-A-228450451-d362a3a4",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/0fa54c7d8a2c061202e61d75b805661c1e89a76d",
"target": {
"function": "BNEP_ConnectResp",
"file": "stack/bnep/bnep_api.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/0fa54c7d8a2c061202e61d75b805661c1e89a76d"
],
"types": [
"ID"
],
"spl": "2022-12-01",
"severity": "Moderate"
}
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"19615635629939757925767189986436799647",
"207990587364688167640515750653759914052",
"274620203780754120125403676728619555520",
"32405815071143783313761956769936829827"
]
},
"id": "ASB-A-228450451-27e16e04",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/0fa54c7d8a2c061202e61d75b805661c1e89a76d",
"target": {
"file": "stack/bnep/bnep_api.cc"
}
},
{
"digest": {
"length": 1562.0,
"function_hash": "251628678351054005449541836964376859324"
},
"id": "ASB-A-228450451-2bd73671",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/0fa54c7d8a2c061202e61d75b805661c1e89a76d",
"target": {
"function": "BNEP_ConnectResp",
"file": "stack/bnep/bnep_api.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/0fa54c7d8a2c061202e61d75b805661c1e89a76d"
],
"types": [
"ID"
],
"spl": "2022-12-01",
"severity": "Moderate"
}
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"19615635629939757925767189986436799647",
"207990587364688167640515750653759914052",
"274620203780754120125403676728619555520",
"32405815071143783313761956769936829827"
]
},
"id": "ASB-A-228450451-4fcbe8a0",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/0fa54c7d8a2c061202e61d75b805661c1e89a76d",
"target": {
"file": "stack/bnep/bnep_api.cc"
}
},
{
"digest": {
"length": 1562.0,
"function_hash": "251628678351054005449541836964376859324"
},
"id": "ASB-A-228450451-4ffc2e49",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/0fa54c7d8a2c061202e61d75b805661c1e89a76d",
"target": {
"function": "BNEP_ConnectResp",
"file": "stack/bnep/bnep_api.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/0fa54c7d8a2c061202e61d75b805661c1e89a76d"
],
"types": [
"ID"
],
"spl": "2022-12-01",
"severity": "Moderate"
}
{
"vanir_signatures": [
{
"digest": {
"length": 1538.0,
"function_hash": "134753087569954871622545896418553395064"
},
"id": "ASB-A-228450451-64dcb2f6",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/644f250acd25ef47950c39349eea6fbfbdd41c14",
"target": {
"function": "BNEP_ConnectResp",
"file": "system/stack/bnep/bnep_api.cc"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"19615635629939757925767189986436799647",
"207990587364688167640515750653759914052",
"274620203780754120125403676728619555520",
"32405815071143783313761956769936829827"
]
},
"id": "ASB-A-228450451-8be034e1",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/644f250acd25ef47950c39349eea6fbfbdd41c14",
"target": {
"file": "system/stack/bnep/bnep_api.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/644f250acd25ef47950c39349eea6fbfbdd41c14"
],
"types": [
"ID"
],
"spl": "2022-12-01",
"severity": "Moderate"
}