In gattdbgopname of gattutils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "match_only_versions": [ "13-next" ], "digest": { "length": 304.0, "function_hash": "108495142603941355380161969255262114895" }, "id": "PUB-A-260079141-6c7d4e57", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/8f013f79801ae1bfb6daa37dbe306fe36a33e678", "deprecated": false, "signature_version": "v1", "target": { "file": "system/stack/gatt/gatt_utils.cc", "function": "gatt_dbg_op_name" }, "signature_type": "Function" }, { "match_only_versions": [ "13-next" ], "digest": { "threshold": 0.9, "line_hashes": [ "306877655781735731004057265056922626020", "180968606853377423050043405577807002284", "298162746033297610771349635992227937250", "35194271448480591414831634923850904476", "172527840135690030660520372750640809726", "215095923846177409187068728242968229650", "224157642708441971204992002044391361658" ] }, "id": "PUB-A-260079141-af1f4ce8", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/8f013f79801ae1bfb6daa37dbe306fe36a33e678", "deprecated": false, "signature_version": "v1", "target": { "file": "system/stack/gatt/gatt_utils.cc" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/8f013f79801ae1bfb6daa37dbe306fe36a33e678" ], "spl": "2023-06-01", "severity": "Moderate", "types": [ "ID" ] }