In btifinhfclientgenericevt of btifhf_client.cc, there is a possible Bluetooth service crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "length": 592.0, "function_hash": "100983578932973266273128197855008333736" }, "id": "PUB-A-180420059-06226d93", "source": "https://android.googlesource.com/platform/system/bt/+/1924e011a8770edcc8430702114ed06b6c11c5ab", "deprecated": false, "signature_version": "v1", "target": { "file": "btif/src/btif_hf_client.cc", "function": "btif_in_hf_client_generic_evt" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "186000689719512910692076778162002460461", "295237246237395290570544931291249859846", "136626929413539361612694698853879259238", "61864395386903211023641912611902541733" ] }, "id": "PUB-A-180420059-2892994a", "source": "https://android.googlesource.com/platform/system/bt/+/1924e011a8770edcc8430702114ed06b6c11c5ab", "deprecated": false, "signature_version": "v1", "target": { "file": "btif/src/btif_hf_client.cc" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/system/bt/+/1924e011a8770edcc8430702114ed06b6c11c5ab" ], "spl": "2021-12-01", "severity": "Moderate", "types": [ "DoS" ] }