In BTAGATTSHandleValueIndication of btagattsapi.cc, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/4f00ec98b6621b0fa89eebf829851f4d8f02303f" ], "severity": "Moderate", "types": [ "EoP" ], "spl": "2023-06-01", "vanir_signatures": [ { "target": { "file": "system/bta/gatt/bta_gatts_api.cc" }, "id": "PUB-A-245915315-91a4b579", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "173433427464343232030996065385142546900", "175381008152256785464226710436349548108", "292261872986763794577689858678727794970", "24728948674180896011306320165118087497" ] }, "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/4f00ec98b6621b0fa89eebf829851f4d8f02303f", "signature_type": "Line", "signature_version": "v1" }, { "target": { "file": "system/bta/gatt/bta_gatts_api.cc", "function": "BTA_GATTS_HandleValueIndication" }, "id": "PUB-A-245915315-95d0dfc6", "deprecated": false, "digest": { "function_hash": "91195820499357571368665567679513203816", "length": 419.0 }, "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/4f00ec98b6621b0fa89eebf829851f4d8f02303f", "signature_type": "Function", "signature_version": "v1" } ] }
{ "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/a3c7e6372846fb89c3c46bbf54f973f9f2311824" ], "severity": "Moderate", "types": [ "EoP" ], "spl": "2023-06-01", "vanir_signatures": [ { "target": { "file": "system/bta/gatt/bta_gatts_api.cc", "function": "BTA_GATTS_HandleValueIndication" }, "id": "PUB-A-245915315-11f86288", "deprecated": false, "digest": { "function_hash": "91195820499357571368665567679513203816", "length": 419.0 }, "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/a3c7e6372846fb89c3c46bbf54f973f9f2311824", "signature_type": "Function", "signature_version": "v1" }, { "target": { "file": "system/bta/gatt/bta_gatts_api.cc" }, "id": "PUB-A-245915315-e3d3f56e", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "173433427464343232030996065385142546900", "175381008152256785464226710436349548108", "292261872986763794577689858678727794970", "24728948674180896011306320165118087497" ] }, "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/a3c7e6372846fb89c3c46bbf54f973f9f2311824", "signature_type": "Line", "signature_version": "v1" } ] }