In btifa2dpsinkcommandready of btifa2dpsink.cc, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "length": 764.0, "function_hash": "168199023650577324740473217060957518896" }, "id": "PUB-A-243922806-2a6eed81", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/9817ef5e94eca59e666b06f51726cf42ad795a8b", "deprecated": false, "signature_version": "v1", "target": { "file": "system/btif/src/btif_a2dp_sink.cc", "function": "btif_a2dp_sink_command_ready" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "141359719233861400509058078807417248523", "257323838391449703508987695826986610788", "297051908284673274171922458888129311125", "127823624903376876452744620997162483473", "216233060177106980018343518428829629871" ] }, "id": "PUB-A-243922806-bef1d320", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/9817ef5e94eca59e666b06f51726cf42ad795a8b", "deprecated": false, "signature_version": "v1", "target": { "file": "system/btif/src/btif_a2dp_sink.cc" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/9817ef5e94eca59e666b06f51726cf42ad795a8b" ], "spl": "2022-12-01", "severity": "Moderate", "types": [ "ID" ] }