In multiple locations, there is a possible out of bounds write due to a use after free. This could lead to remote code execution over Bluetooth, if HFP support is enabled, with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "335368174811882274076803387340832741725", "255031183291357723729392712308822489280", "89229534733456882219803669197240033416", "150124077756793490750368150011669814184" ] }, "id": "ASB-A-291281168-5e5dfd63", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/0a9516473b961ec87dd404e7ec7ec08878863007", "deprecated": false, "signature_version": "v1", "target": { "file": "system/stack/sdp/sdp_discovery.cc" }, "signature_type": "Line" }, { "digest": { "length": 3344.0, "function_hash": "310920496597318753910233274266619904423" }, "id": "ASB-A-291281168-8d34969b", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/0a9516473b961ec87dd404e7ec7ec08878863007", "deprecated": false, "signature_version": "v1", "target": { "file": "system/stack/sdp/sdp_discovery.cc", "function": "process_service_search_attr_rsp" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "254894881002214492044306048939760605142", "159748619053514283753669561004036297346", "25363138603644386313863572322508944179", "269601458157509761513275739540777980366" ] }, "id": "ASB-A-291281168-a312c968", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/0a9516473b961ec87dd404e7ec7ec08878863007", "deprecated": false, "signature_version": "v1", "target": { "file": "system/bta/hf_client/bta_hf_client_sdp.cc" }, "signature_type": "Line" }, { "digest": { "length": 1278.0, "function_hash": "55358988029788956911272662740912552981" }, "id": "ASB-A-291281168-e9e9ce56", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/0a9516473b961ec87dd404e7ec7ec08878863007", "deprecated": false, "signature_version": "v1", "target": { "file": "system/bta/hf_client/bta_hf_client_sdp.cc", "function": "bta_hf_client_do_disc" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/0a9516473b961ec87dd404e7ec7ec08878863007" ], "spl": "2025-03-01", "severity": "Critical", "types": [ "RCE" ] }