In oncreaterecordevent of btifsdp_server.cc, there is a possible out of bounds read due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"fixes": [
"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b45b847923b0961a72c007fabf241aeb288555a7"
],
"severity": "Moderate",
"types": [
"DoS"
],
"spl": "2023-06-01",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b45b847923b0961a72c007fabf241aeb288555a7",
"digest": {
"length": 930.0,
"function_hash": "20097229009039841849162195789412494020"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"target": {
"file": "system/btif/src/btif_sdp_server.cc",
"function": "on_create_record_event"
},
"id": "PUB-A-263545186-46fb1e4b"
},
{
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b45b847923b0961a72c007fabf241aeb288555a7",
"digest": {
"line_hashes": [
"317788044459968284923696034204101275166",
"41588262629951368502940914956533878477",
"95628027711683019450085083107078831723",
"304214588498363512538106009430986837166",
"201022218695380493521015868191795181323",
"149003916611454817267061666945564548709"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"target": {
"file": "system/btif/src/btif_sdp_server.cc"
},
"id": "PUB-A-263545186-6820681e"
}
]
}
{
"fixes": [
"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b45b847923b0961a72c007fabf241aeb288555a7"
],
"severity": "Moderate",
"types": [
"DoS"
],
"spl": "2023-06-01",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b45b847923b0961a72c007fabf241aeb288555a7",
"digest": {
"line_hashes": [
"317788044459968284923696034204101275166",
"41588262629951368502940914956533878477",
"95628027711683019450085083107078831723",
"304214588498363512538106009430986837166",
"201022218695380493521015868191795181323",
"149003916611454817267061666945564548709"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"target": {
"file": "system/btif/src/btif_sdp_server.cc"
},
"id": "PUB-A-263545186-74986535"
},
{
"source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b45b847923b0961a72c007fabf241aeb288555a7",
"digest": {
"length": 930.0,
"function_hash": "20097229009039841849162195789412494020"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"target": {
"file": "system/btif/src/btif_sdp_server.cc",
"function": "on_create_record_event"
},
"id": "PUB-A-263545186-e4b28e5e"
}
]
}