In avdtmsgind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "291121899986190632954558531092622720636", "145485880068509586563865574044950578055", "236604861184405476897001877115365783460", "162556421373855455052121016183079354238", "283785321425543417081153347573944754301", "314592963219822661814482431325513627637", "213375627068001655805525833708755971092", "60345347931178594599383642155093729954", "232881515703603029002002586106176935855" ] }, "id": "ASB-A-273995284-89b11a98", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/ca504bbacbdb2478cf18103c28ca39915bc352f6", "deprecated": false, "signature_version": "v1", "target": { "file": "system/stack/avdt/avdt_msg.cc" }, "signature_type": "Line" }, { "digest": { "threshold": 0.9, "line_hashes": [ "69968497529221303174354349176262428972", "289267339819583124441987779324406424110", "210875894870981578955181235640352806598", "232881515703603029002002586106176935855", "298765360413203219284747084932649921103" ] }, "id": "ASB-A-273995284-a77d54bd", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/6012433653b2770ddb67f5d6e9042e8ff6f8d66c", "deprecated": false, "signature_version": "v1", "target": { "file": "system/stack/avdt/avdt_msg.cc" }, "signature_type": "Line" }, { "digest": { "length": 3934.0, "function_hash": "17364776682207328621562279625673091583" }, "id": "ASB-A-273995284-c6988bad", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/ca504bbacbdb2478cf18103c28ca39915bc352f6", "deprecated": false, "signature_version": "v1", "target": { "file": "system/stack/avdt/avdt_msg.cc", "function": "avdt_msg_ind" }, "signature_type": "Function" }, { "digest": { "length": 3611.0, "function_hash": "101213322258309175509044928261249359797" }, "id": "ASB-A-273995284-d749451d", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/6012433653b2770ddb67f5d6e9042e8ff6f8d66c", "deprecated": false, "signature_version": "v1", "target": { "file": "system/stack/avdt/avdt_msg.cc", "function": "avdt_msg_ind" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/6012433653b2770ddb67f5d6e9042e8ff6f8d66c", "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/ca504bbacbdb2478cf18103c28ca39915bc352f6" ], "spl": "2025-04-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 3591.0, "function_hash": "275031440224446623701712737192977390752" }, "id": "ASB-A-273995284-41beb74d", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/359bdee195ff58652663b2721e966b2604a93f94", "deprecated": false, "signature_version": "v1", "target": { "file": "system/stack/avdt/avdt_msg.cc", "function": "avdt_msg_ind" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "289267339819583124441987779324406424110", "210875894870981578955181235640352806598", "127072241333684706305506437777635863312", "96166965579290052119536940010839083498" ] }, "id": "ASB-A-273995284-9dd84d23", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/359bdee195ff58652663b2721e966b2604a93f94", "deprecated": false, "signature_version": "v1", "target": { "file": "system/stack/avdt/avdt_msg.cc" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/359bdee195ff58652663b2721e966b2604a93f94" ], "spl": "2025-04-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "289267339819583124441987779324406424110", "210875894870981578955181235640352806598", "127072241333684706305506437777635863312", "96166965579290052119536940010839083498" ] }, "id": "ASB-A-273995284-06f37d23", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/359bdee195ff58652663b2721e966b2604a93f94", "deprecated": false, "signature_version": "v1", "target": { "file": "system/stack/avdt/avdt_msg.cc" }, "signature_type": "Line" }, { "digest": { "length": 3591.0, "function_hash": "275031440224446623701712737192977390752" }, "id": "ASB-A-273995284-0b6777c2", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/359bdee195ff58652663b2721e966b2604a93f94", "deprecated": false, "signature_version": "v1", "target": { "file": "system/stack/avdt/avdt_msg.cc", "function": "avdt_msg_ind" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/359bdee195ff58652663b2721e966b2604a93f94" ], "spl": "2025-04-01", "severity": "High", "types": [ "EoP" ] }