In attpbuildvaluecmd of attprotocol.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b927f3fb660dafaf97b2fa0398353a8c39125efc", "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/074b81c0b0352f254735b6bbd60b0501ac55096b", "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/09e48e0d5377ef56a556f9f05ed3e3e97849475e" ], "spl": "2024-03-01", "types": [ "RCE" ], "severity": "Critical" }
{ "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/a0d4425c3964f99f589d449deed2f1bbe520218c", "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/6dbe94fe556ef67f3bbb7d7bb2da3320d68619df", "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/4ae5e736813bf2928bfc8c71e3dacf3b78394046" ], "spl": "2024-03-01", "types": [ "RCE" ], "severity": "Critical" }
{ "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/a0d4425c3964f99f589d449deed2f1bbe520218c", "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/6dbe94fe556ef67f3bbb7d7bb2da3320d68619df", "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/4ae5e736813bf2928bfc8c71e3dacf3b78394046" ], "spl": "2024-03-01", "types": [ "RCE" ], "severity": "Critical" }