In btaavrcmsg of btaav_act.cc, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "length": 5765.0, "function_hash": "202031495183167535993362350757088610019" }, "id": "ASB-A-269253349-04d81780", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/436a60c26744ef0699ba49182987467cee4a746b", "deprecated": false, "signature_version": "v1", "target": { "file": "system/bta/av/bta_av_act.cc", "function": "bta_av_rc_msg" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "126063420346306657663512677345875224896", "242319816300548950297038881119232842538", "233258715842497773758930975541940563986", "245693739312668986704721811531529499321" ] }, "id": "ASB-A-269253349-66a38ccb", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/436a60c26744ef0699ba49182987467cee4a746b", "deprecated": false, "signature_version": "v1", "target": { "file": "system/bta/av/bta_av_act.cc" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/436a60c26744ef0699ba49182987467cee4a746b" ], "spl": "2023-09-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 5765.0, "function_hash": "202031495183167535993362350757088610019" }, "id": "ASB-A-269253349-35352c09", "source": "https://android.googlesource.com/platform/system/bt/+/91f6d6215c101acc99a7397c5fb5a12fe6d7b8e9", "deprecated": false, "signature_version": "v1", "target": { "file": "bta/av/bta_av_act.cc", "function": "bta_av_rc_msg" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "126063420346306657663512677345875224896", "242319816300548950297038881119232842538", "233258715842497773758930975541940563986", "245693739312668986704721811531529499321" ] }, "id": "ASB-A-269253349-4c3c669b", "source": "https://android.googlesource.com/platform/system/bt/+/91f6d6215c101acc99a7397c5fb5a12fe6d7b8e9", "deprecated": false, "signature_version": "v1", "target": { "file": "bta/av/bta_av_act.cc" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/system/bt/+/91f6d6215c101acc99a7397c5fb5a12fe6d7b8e9" ], "spl": "2023-09-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 5765.0, "function_hash": "202031495183167535993362350757088610019" }, "id": "ASB-A-269253349-326f2045", "source": "https://android.googlesource.com/platform/system/bt/+/91f6d6215c101acc99a7397c5fb5a12fe6d7b8e9", "deprecated": false, "signature_version": "v1", "target": { "file": "bta/av/bta_av_act.cc", "function": "bta_av_rc_msg" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "126063420346306657663512677345875224896", "242319816300548950297038881119232842538", "233258715842497773758930975541940563986", "245693739312668986704721811531529499321" ] }, "id": "ASB-A-269253349-dfbf133e", "source": "https://android.googlesource.com/platform/system/bt/+/91f6d6215c101acc99a7397c5fb5a12fe6d7b8e9", "deprecated": false, "signature_version": "v1", "target": { "file": "bta/av/bta_av_act.cc" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/system/bt/+/91f6d6215c101acc99a7397c5fb5a12fe6d7b8e9" ], "spl": "2023-09-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "126063420346306657663512677345875224896", "242319816300548950297038881119232842538", "233258715842497773758930975541940563986", "245693739312668986704721811531529499321" ] }, "id": "ASB-A-269253349-589203c3", "source": "https://android.googlesource.com/platform/system/bt/+/91f6d6215c101acc99a7397c5fb5a12fe6d7b8e9", "deprecated": false, "signature_version": "v1", "target": { "file": "bta/av/bta_av_act.cc" }, "signature_type": "Line" }, { "digest": { "length": 5765.0, "function_hash": "202031495183167535993362350757088610019" }, "id": "ASB-A-269253349-9203f115", "source": "https://android.googlesource.com/platform/system/bt/+/91f6d6215c101acc99a7397c5fb5a12fe6d7b8e9", "deprecated": false, "signature_version": "v1", "target": { "file": "bta/av/bta_av_act.cc", "function": "bta_av_rc_msg" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/system/bt/+/91f6d6215c101acc99a7397c5fb5a12fe6d7b8e9" ], "spl": "2023-09-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "126063420346306657663512677345875224896", "242319816300548950297038881119232842538", "233258715842497773758930975541940563986", "245693739312668986704721811531529499321" ] }, "id": "ASB-A-269253349-3e94ced0", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/d3ee136851de30261e56c62fbb488541dc564b94", "deprecated": false, "signature_version": "v1", "target": { "file": "system/bta/av/bta_av_act.cc" }, "signature_type": "Line" }, { "digest": { "length": 5765.0, "function_hash": "202031495183167535993362350757088610019" }, "id": "ASB-A-269253349-751abff0", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/d3ee136851de30261e56c62fbb488541dc564b94", "deprecated": false, "signature_version": "v1", "target": { "file": "system/bta/av/bta_av_act.cc", "function": "bta_av_rc_msg" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/d3ee136851de30261e56c62fbb488541dc564b94" ], "spl": "2023-09-01", "severity": "High", "types": [ "EoP" ] }