In btuhcifprocessevent of btuhcif.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "40767343341832141217188341133684849434", "54024266049303169283572748630648247895", "300420770289793361418986569480340264145", "180421665534134034300655699301545002188" ] }, "id": "PUB-A-167759047-383064b1", "source": "https://android.googlesource.com/platform/system/bt/+/3ffe74d086f4bfba370749c55d315d881d77816c", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/include/hci_evt_length.h" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/system/bt/+/3ffe74d086f4bfba370749c55d315d881d77816c" ], "spl": "2021-12-01", "severity": "Moderate", "types": [ "ID" ] }