In btmbleaddresolvinglistentrycomplete of btmbleprivacy.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
{ "types": [ "ID" ], "severity": "Moderate", "vanir_signatures": [ { "digest": { "function_hash": "314825647421878740072628518030256069639", "length": 608.0 }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b56c6c90d7293cdeb49bc23db18eab5444e27253", "id": "PUB-A-260078907-66a5bd6b", "signature_type": "Function", "target": { "file": "system/stack/btm/btm_ble_privacy.cc", "function": "btm_ble_add_resolving_list_entry_complete" } }, { "digest": { "threshold": 0.9, "line_hashes": [ "254997327880531539884238603739185779452", "53808917594966300287303033785326462055", "206818640049023163158263720926008378437", "162429994603533292071809646757466600543" ] }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b56c6c90d7293cdeb49bc23db18eab5444e27253", "id": "PUB-A-260078907-682654c5", "signature_type": "Line", "target": { "file": "system/stack/btm/btm_ble_privacy.cc" } } ], "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b56c6c90d7293cdeb49bc23db18eab5444e27253", "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/64edeb6a5bcc04c32c44efd2a466e8951b4ae078" ], "spl": "2023-06-01" }
{ "types": [ "ID" ], "severity": "Moderate", "vanir_signatures": [ { "digest": { "function_hash": "314825647421878740072628518030256069639", "length": 608.0 }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/73827ac555cd4faa98510a18ee008ca78d142929", "id": "PUB-A-260078907-7c8d5e26", "signature_type": "Function", "target": { "file": "system/stack/btm/btm_ble_privacy.cc", "function": "btm_ble_add_resolving_list_entry_complete" } }, { "digest": { "threshold": 0.9, "line_hashes": [ "254997327880531539884238603739185779452", "53808917594966300287303033785326462055", "206818640049023163158263720926008378437", "162429994603533292071809646757466600543" ] }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/73827ac555cd4faa98510a18ee008ca78d142929", "id": "PUB-A-260078907-89430c39", "signature_type": "Line", "target": { "file": "system/stack/btm/btm_ble_privacy.cc" } } ], "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/73827ac555cd4faa98510a18ee008ca78d142929", "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/27200cfeed0dbfa7daa7c1825d62df47ad13465d" ], "spl": "2023-06-01" }