In avdtscbhdlwritereq of avdtscbact.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"144940686777104710571966521297968008422",
"219232503302018254571802627114048278085",
"269556321489143915640961737916683630537",
"46125424436412511154327772841996970179"
]
},
"id": "ASB-A-242535997-6572e876",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/be058b1eb979599c7d515463a1e9f7ec1b2344c4",
"deprecated": false,
"target": {
"file": "system/stack/avdt/avdt_scb_act.cc"
},
"signature_version": "v1"
},
{
"digest": {
"function_hash": "21316893359240151507608382100880029294",
"length": 925.0
},
"id": "ASB-A-242535997-bc283278",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/be058b1eb979599c7d515463a1e9f7ec1b2344c4",
"deprecated": false,
"target": {
"function": "avdt_scb_hdl_write_req",
"file": "system/stack/avdt/avdt_scb_act.cc"
},
"signature_version": "v1"
}
],
"types": [
"EoP"
],
"spl": "2023-03-01",
"fixes": [
"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/be058b1eb979599c7d515463a1e9f7ec1b2344c4"
],
"severity": "High"
}
{
"vanir_signatures": [
{
"digest": {
"function_hash": "21316893359240151507608382100880029294",
"length": 925.0
},
"id": "ASB-A-242535997-a9ab0d67",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/bt/+/eca4a3cdb0da240496341f546a57397434ec85dd",
"deprecated": false,
"target": {
"function": "avdt_scb_hdl_write_req",
"file": "stack/avdt/avdt_scb_act.cc"
},
"signature_version": "v1"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"144940686777104710571966521297968008422",
"219232503302018254571802627114048278085",
"269556321489143915640961737916683630537",
"46125424436412511154327772841996970179"
]
},
"id": "ASB-A-242535997-db40fffd",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/bt/+/eca4a3cdb0da240496341f546a57397434ec85dd",
"deprecated": false,
"target": {
"file": "stack/avdt/avdt_scb_act.cc"
},
"signature_version": "v1"
}
],
"types": [
"EoP"
],
"spl": "2023-03-01",
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/eca4a3cdb0da240496341f546a57397434ec85dd"
],
"severity": "High"
}
{
"vanir_signatures": [
{
"digest": {
"function_hash": "21316893359240151507608382100880029294",
"length": 925.0
},
"id": "ASB-A-242535997-ae3001ab",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/789d4bc617da23dc86d288c53c80a242d3a6850f",
"deprecated": false,
"target": {
"function": "avdt_scb_hdl_write_req",
"file": "system/stack/avdt/avdt_scb_act.cc"
},
"signature_version": "v1"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"144940686777104710571966521297968008422",
"219232503302018254571802627114048278085",
"269556321489143915640961737916683630537",
"46125424436412511154327772841996970179"
]
},
"id": "ASB-A-242535997-ee4fddd8",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/789d4bc617da23dc86d288c53c80a242d3a6850f",
"deprecated": false,
"target": {
"file": "system/stack/avdt/avdt_scb_act.cc"
},
"signature_version": "v1"
}
],
"types": [
"EoP"
],
"spl": "2023-03-01",
"fixes": [
"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/789d4bc617da23dc86d288c53c80a242d3a6850f"
],
"severity": "High"
}