In avdtmsgasmbl of avdt_msg.cc, there is a possible out of bounds write due to an integer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"205503213461534524996964454821878364842",
"123841091169846678710746539856086903864",
"221252012638599075510746473711720122832",
"265981268881668604892832250504896933543",
"166970167131151963096032843008481224167",
"74076694523211457375836683700949727555",
"244151524030131126660541297271967691970"
]
},
"id": "ASB-A-280633699-7490fa0b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/bf9449a704c2983861dbe0ede9ab660e42826179",
"target": {
"file": "system/stack/avdt/avdt_msg.cc"
}
},
{
"digest": {
"length": 2302.0,
"function_hash": "223273454540487395414285899053428066891"
},
"id": "ASB-A-280633699-f12d3194",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/bf9449a704c2983861dbe0ede9ab660e42826179",
"target": {
"function": "avdt_msg_asmbl",
"file": "system/stack/avdt/avdt_msg.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/bf9449a704c2983861dbe0ede9ab660e42826179"
],
"types": [
"EoP"
],
"spl": "2023-09-01",
"severity": "High"
}
{
"vanir_signatures": [
{
"digest": {
"length": 2302.0,
"function_hash": "223273454540487395414285899053428066891"
},
"id": "ASB-A-280633699-04893c90",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/bf9449a704c2983861dbe0ede9ab660e42826179",
"target": {
"function": "avdt_msg_asmbl",
"file": "system/stack/avdt/avdt_msg.cc"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"205503213461534524996964454821878364842",
"123841091169846678710746539856086903864",
"221252012638599075510746473711720122832",
"265981268881668604892832250504896933543",
"166970167131151963096032843008481224167",
"74076694523211457375836683700949727555",
"244151524030131126660541297271967691970"
]
},
"id": "ASB-A-280633699-0c923cb5",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/bf9449a704c2983861dbe0ede9ab660e42826179",
"target": {
"file": "system/stack/avdt/avdt_msg.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/bf9449a704c2983861dbe0ede9ab660e42826179"
],
"types": [
"EoP"
],
"spl": "2023-09-01",
"severity": "High"
}