In btmbleaddresolvinglistentrycomplete of btmbleprivacy.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"length": 608.0,
"function_hash": "314825647421878740072628518030256069639"
},
"id": "PUB-A-260078907-66a5bd6b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b56c6c90d7293cdeb49bc23db18eab5444e27253",
"target": {
"function": "btm_ble_add_resolving_list_entry_complete",
"file": "system/stack/btm/btm_ble_privacy.cc"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"254997327880531539884238603739185779452",
"53808917594966300287303033785326462055",
"206818640049023163158263720926008378437",
"162429994603533292071809646757466600543"
]
},
"id": "PUB-A-260078907-682654c5",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b56c6c90d7293cdeb49bc23db18eab5444e27253",
"target": {
"file": "system/stack/btm/btm_ble_privacy.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b56c6c90d7293cdeb49bc23db18eab5444e27253",
"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/64edeb6a5bcc04c32c44efd2a466e8951b4ae078"
],
"types": [
"ID"
],
"spl": "2023-06-01",
"severity": "Moderate"
}
{
"vanir_signatures": [
{
"digest": {
"length": 608.0,
"function_hash": "314825647421878740072628518030256069639"
},
"id": "PUB-A-260078907-7c8d5e26",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/73827ac555cd4faa98510a18ee008ca78d142929",
"target": {
"function": "btm_ble_add_resolving_list_entry_complete",
"file": "system/stack/btm/btm_ble_privacy.cc"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"254997327880531539884238603739185779452",
"53808917594966300287303033785326462055",
"206818640049023163158263720926008378437",
"162429994603533292071809646757466600543"
]
},
"id": "PUB-A-260078907-89430c39",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/73827ac555cd4faa98510a18ee008ca78d142929",
"target": {
"file": "system/stack/btm/btm_ble_privacy.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/73827ac555cd4faa98510a18ee008ca78d142929",
"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/27200cfeed0dbfa7daa7c1825d62df47ad13465d"
],
"types": [
"ID"
],
"spl": "2023-06-01",
"severity": "Moderate"
}