In btaavrcmsg of btaav_act.cc, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"spl": "2023-09-01",
"fixes": [
"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/436a60c26744ef0699ba49182987467cee4a746b"
],
"types": [
"EoP"
],
"vanir_signatures": [
{
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 5765.0,
"function_hash": "202031495183167535993362350757088610019"
},
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/436a60c26744ef0699ba49182987467cee4a746b",
"target": {
"function": "bta_av_rc_msg",
"file": "system/bta/av/bta_av_act.cc"
},
"id": "ASB-A-269253349-04d81780"
},
{
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"126063420346306657663512677345875224896",
"242319816300548950297038881119232842538",
"233258715842497773758930975541940563986",
"245693739312668986704721811531529499321"
],
"threshold": 0.9
},
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/436a60c26744ef0699ba49182987467cee4a746b",
"target": {
"file": "system/bta/av/bta_av_act.cc"
},
"id": "ASB-A-269253349-66a38ccb"
}
],
"severity": "High"
}{
"spl": "2023-09-01",
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/91f6d6215c101acc99a7397c5fb5a12fe6d7b8e9"
],
"types": [
"EoP"
],
"vanir_signatures": [
{
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 5765.0,
"function_hash": "202031495183167535993362350757088610019"
},
"source": "https://android.googlesource.com/platform/system/bt/+/91f6d6215c101acc99a7397c5fb5a12fe6d7b8e9",
"target": {
"function": "bta_av_rc_msg",
"file": "bta/av/bta_av_act.cc"
},
"id": "ASB-A-269253349-35352c09"
},
{
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"126063420346306657663512677345875224896",
"242319816300548950297038881119232842538",
"233258715842497773758930975541940563986",
"245693739312668986704721811531529499321"
],
"threshold": 0.9
},
"source": "https://android.googlesource.com/platform/system/bt/+/91f6d6215c101acc99a7397c5fb5a12fe6d7b8e9",
"target": {
"file": "bta/av/bta_av_act.cc"
},
"id": "ASB-A-269253349-4c3c669b"
}
],
"severity": "High"
}{
"spl": "2023-09-01",
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/91f6d6215c101acc99a7397c5fb5a12fe6d7b8e9"
],
"types": [
"EoP"
],
"vanir_signatures": [
{
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 5765.0,
"function_hash": "202031495183167535993362350757088610019"
},
"source": "https://android.googlesource.com/platform/system/bt/+/91f6d6215c101acc99a7397c5fb5a12fe6d7b8e9",
"target": {
"function": "bta_av_rc_msg",
"file": "bta/av/bta_av_act.cc"
},
"id": "ASB-A-269253349-326f2045"
},
{
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"126063420346306657663512677345875224896",
"242319816300548950297038881119232842538",
"233258715842497773758930975541940563986",
"245693739312668986704721811531529499321"
],
"threshold": 0.9
},
"source": "https://android.googlesource.com/platform/system/bt/+/91f6d6215c101acc99a7397c5fb5a12fe6d7b8e9",
"target": {
"file": "bta/av/bta_av_act.cc"
},
"id": "ASB-A-269253349-dfbf133e"
}
],
"severity": "High"
}{
"spl": "2023-09-01",
"fixes": [
"https://android.googlesource.com/platform/system/bt/+/91f6d6215c101acc99a7397c5fb5a12fe6d7b8e9"
],
"types": [
"EoP"
],
"vanir_signatures": [
{
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"126063420346306657663512677345875224896",
"242319816300548950297038881119232842538",
"233258715842497773758930975541940563986",
"245693739312668986704721811531529499321"
],
"threshold": 0.9
},
"source": "https://android.googlesource.com/platform/system/bt/+/91f6d6215c101acc99a7397c5fb5a12fe6d7b8e9",
"target": {
"file": "bta/av/bta_av_act.cc"
},
"id": "ASB-A-269253349-589203c3"
},
{
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 5765.0,
"function_hash": "202031495183167535993362350757088610019"
},
"source": "https://android.googlesource.com/platform/system/bt/+/91f6d6215c101acc99a7397c5fb5a12fe6d7b8e9",
"target": {
"function": "bta_av_rc_msg",
"file": "bta/av/bta_av_act.cc"
},
"id": "ASB-A-269253349-9203f115"
}
],
"severity": "High"
}{
"spl": "2023-09-01",
"fixes": [
"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/d3ee136851de30261e56c62fbb488541dc564b94"
],
"types": [
"EoP"
],
"vanir_signatures": [
{
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"126063420346306657663512677345875224896",
"242319816300548950297038881119232842538",
"233258715842497773758930975541940563986",
"245693739312668986704721811531529499321"
],
"threshold": 0.9
},
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/d3ee136851de30261e56c62fbb488541dc564b94",
"target": {
"file": "system/bta/av/bta_av_act.cc"
},
"id": "ASB-A-269253349-3e94ced0"
},
{
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 5765.0,
"function_hash": "202031495183167535993362350757088610019"
},
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/d3ee136851de30261e56c62fbb488541dc564b94",
"target": {
"function": "bta_av_rc_msg",
"file": "system/bta/av/bta_av_act.cc"
},
"id": "ASB-A-269253349-751abff0"
}
],
"severity": "High"
}