In avctlcbmsgasmbl of avctlcb_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"173584054749471213542059671671466609370",
"218272014920384491034865323393805809107",
"213647027907871969227418315119428298185",
"9928675793482950772906846926328496605",
"315874836010301295655053817557664409089",
"234310698468177673899024177910053053341",
"131546008756469857604060041408456869966",
"52641849214879142077314346935312098238"
]
},
"id": "ASB-A-230867224-4c8c42f7",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/769f55450bd2eb94ddb9080f730e404de7716bda",
"target": {
"file": "stack/avct/avct_lcb_act.cc"
}
},
{
"digest": {
"length": 2079.0,
"function_hash": "215894916147553160587423900392199587617"
},
"id": "ASB-A-230867224-8cf5a75b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/769f55450bd2eb94ddb9080f730e404de7716bda",
"target": {
"function": "avct_lcb_msg_asmbl",
"file": "stack/avct/avct_lcb_act.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/769f55450bd2eb94ddb9080f730e404de7716bda"
],
"types": [
"RCE"
],
"spl": "2022-12-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"length": 2079.0,
"function_hash": "215894916147553160587423900392199587617"
},
"id": "ASB-A-230867224-9554efac",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/f67ea88c64d62e81c9a804c67ff06c52a6920d39",
"target": {
"function": "avct_lcb_msg_asmbl",
"file": "stack/avct/avct_lcb_act.cc"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"173584054749471213542059671671466609370",
"218272014920384491034865323393805809107",
"213647027907871969227418315119428298185",
"9928675793482950772906846926328496605",
"315874836010301295655053817557664409089",
"234310698468177673899024177910053053341",
"131546008756469857604060041408456869966",
"52641849214879142077314346935312098238"
]
},
"id": "ASB-A-230867224-fb7dc3b0",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/f67ea88c64d62e81c9a804c67ff06c52a6920d39",
"target": {
"file": "stack/avct/avct_lcb_act.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/f67ea88c64d62e81c9a804c67ff06c52a6920d39"
],
"types": [
"RCE"
],
"spl": "2022-12-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"length": 2079.0,
"function_hash": "215894916147553160587423900392199587617"
},
"id": "ASB-A-230867224-11d2a2f6",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/2992109ab975def57192c5e3d40078e69b1e8717",
"target": {
"function": "avct_lcb_msg_asmbl",
"file": "stack/avct/avct_lcb_act.cc"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"315874836010301295655053817557664409089",
"234310698468177673899024177910053053341",
"131546008756469857604060041408456869966",
"52641849214879142077314346935312098238"
]
},
"id": "ASB-A-230867224-ace0e056",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/2992109ab975def57192c5e3d40078e69b1e8717",
"target": {
"file": "stack/avct/avct_lcb_act.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/2992109ab975def57192c5e3d40078e69b1e8717"
],
"types": [
"RCE"
],
"spl": "2022-12-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"315874836010301295655053817557664409089",
"234310698468177673899024177910053053341",
"131546008756469857604060041408456869966",
"52641849214879142077314346935312098238"
]
},
"id": "ASB-A-230867224-c8721c22",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/2992109ab975def57192c5e3d40078e69b1e8717",
"target": {
"file": "stack/avct/avct_lcb_act.cc"
}
},
{
"digest": {
"length": 2079.0,
"function_hash": "215894916147553160587423900392199587617"
},
"id": "ASB-A-230867224-d989ff4f",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/2992109ab975def57192c5e3d40078e69b1e8717",
"target": {
"function": "avct_lcb_msg_asmbl",
"file": "stack/avct/avct_lcb_act.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/2992109ab975def57192c5e3d40078e69b1e8717"
],
"types": [
"RCE"
],
"spl": "2022-12-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"315874836010301295655053817557664409089",
"234310698468177673899024177910053053341",
"131546008756469857604060041408456869966",
"52641849214879142077314346935312098238"
]
},
"id": "ASB-A-230867224-52c0fda8",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/6b4acc4d439bf6e66c520819de068eb486724e05",
"target": {
"file": "system/stack/avct/avct_lcb_act.cc"
}
},
{
"digest": {
"length": 2079.0,
"function_hash": "215894916147553160587423900392199587617"
},
"id": "ASB-A-230867224-ee64cc06",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/6b4acc4d439bf6e66c520819de068eb486724e05",
"target": {
"function": "avct_lcb_msg_asmbl",
"file": "system/stack/avct/avct_lcb_act.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/6b4acc4d439bf6e66c520819de068eb486724e05"
],
"types": [
"RCE"
],
"spl": "2022-12-01",
"severity": "High"
}