In oncreaterecordevent of btifsdp_server.cc, there is a possible out of bounds read due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "severity": "Moderate", "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b45b847923b0961a72c007fabf241aeb288555a7" ], "types": [ "DoS" ], "spl": "2023-06-01", "vanir_signatures": [ { "id": "PUB-A-263545186-46fb1e4b", "deprecated": false, "signature_version": "v1", "digest": { "function_hash": "20097229009039841849162195789412494020", "length": 930.0 }, "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b45b847923b0961a72c007fabf241aeb288555a7", "signature_type": "Function", "target": { "function": "on_create_record_event", "file": "system/btif/src/btif_sdp_server.cc" } }, { "id": "PUB-A-263545186-6820681e", "deprecated": false, "signature_version": "v1", "digest": { "line_hashes": [ "317788044459968284923696034204101275166", "41588262629951368502940914956533878477", "95628027711683019450085083107078831723", "304214588498363512538106009430986837166", "201022218695380493521015868191795181323", "149003916611454817267061666945564548709" ], "threshold": 0.9 }, "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b45b847923b0961a72c007fabf241aeb288555a7", "signature_type": "Line", "target": { "file": "system/btif/src/btif_sdp_server.cc" } } ] }
{ "severity": "Moderate", "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b45b847923b0961a72c007fabf241aeb288555a7" ], "types": [ "DoS" ], "spl": "2023-06-01", "vanir_signatures": [ { "id": "PUB-A-263545186-74986535", "deprecated": false, "signature_version": "v1", "digest": { "line_hashes": [ "317788044459968284923696034204101275166", "41588262629951368502940914956533878477", "95628027711683019450085083107078831723", "304214588498363512538106009430986837166", "201022218695380493521015868191795181323", "149003916611454817267061666945564548709" ], "threshold": 0.9 }, "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b45b847923b0961a72c007fabf241aeb288555a7", "signature_type": "Line", "target": { "file": "system/btif/src/btif_sdp_server.cc" } }, { "id": "PUB-A-263545186-e4b28e5e", "deprecated": false, "signature_version": "v1", "digest": { "function_hash": "20097229009039841849162195789412494020", "length": 930.0 }, "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b45b847923b0961a72c007fabf241aeb288555a7", "signature_type": "Function", "target": { "function": "on_create_record_event", "file": "system/btif/src/btif_sdp_server.cc" } } ] }