In removesdprecord of btifsdpserver.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "match_only_versions": [ "13-next" ], "digest": { "threshold": 0.9, "line_hashes": [ "234577341053979416166348750032160090373", "182739720076160360690039348437213757437", "223546810899335391801317515885637318194" ] }, "id": "PUB-A-245517503-8a9c91d9", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b9a94d52c59f55318e7a7d0d5f199e4a633a7782", "deprecated": false, "signature_version": "v1", "target": { "file": "system/btif/src/btif_sdp_server.cc" }, "signature_type": "Line" }, { "match_only_versions": [ "13-next" ], "digest": { "length": 877.0, "function_hash": "69317374448281767407281703466273494736" }, "id": "PUB-A-245517503-d71ae8b1", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b9a94d52c59f55318e7a7d0d5f199e4a633a7782", "deprecated": false, "signature_version": "v1", "target": { "file": "system/btif/src/btif_sdp_server.cc", "function": "remove_sdp_record" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b9a94d52c59f55318e7a7d0d5f199e4a633a7782" ], "spl": "2023-06-01", "severity": "Moderate", "types": [ "ID" ] }