In registernotificationrsp of btif_rc.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"severity": "High",
"fixes": [
"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/daa3efc5e53c8613f4b1a33e095ff6c6460b8d02"
],
"spl": "2023-04-01",
"vanir_signatures": [
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/daa3efc5e53c8613f4b1a33e095ff6c6460b8d02",
"target": {
"function": "register_notification_rsp",
"file": "system/btif/src/btif_rc.cc"
},
"deprecated": false,
"digest": {
"function_hash": "333474244974845735124076347977841360913",
"length": 2481.0
},
"signature_type": "Function",
"id": "ASB-A-245916076-2d5f668e"
},
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/daa3efc5e53c8613f4b1a33e095ff6c6460b8d02",
"target": {
"file": "system/btif/src/btif_rc.cc"
},
"deprecated": false,
"digest": {
"line_hashes": [
"41505634453838932711310759207758210033",
"36457990891724466920911047625859037663",
"75827524418212291543698253757485864423"
],
"threshold": 0.9
},
"signature_type": "Line",
"id": "ASB-A-245916076-ee6bc6ef"
}
],
"types": [
"ID"
]
}
{
"severity": "High",
"fixes": [
"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/daa3efc5e53c8613f4b1a33e095ff6c6460b8d02"
],
"spl": "2023-04-01",
"vanir_signatures": [
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/daa3efc5e53c8613f4b1a33e095ff6c6460b8d02",
"target": {
"file": "system/btif/src/btif_rc.cc"
},
"deprecated": false,
"digest": {
"line_hashes": [
"41505634453838932711310759207758210033",
"36457990891724466920911047625859037663",
"75827524418212291543698253757485864423"
],
"threshold": 0.9
},
"signature_type": "Line",
"id": "ASB-A-245916076-294da57a"
},
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/daa3efc5e53c8613f4b1a33e095ff6c6460b8d02",
"target": {
"function": "register_notification_rsp",
"file": "system/btif/src/btif_rc.cc"
},
"deprecated": false,
"digest": {
"function_hash": "333474244974845735124076347977841360913",
"length": 2481.0
},
"signature_type": "Function",
"id": "ASB-A-245916076-ab9eeb59"
}
],
"types": [
"ID"
]
}