In gattprocessreadbytypersp of gattcl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "length": 4639.0, "function_hash": "42957258101994466047224867379899158865" }, "id": "ASB-A-158833854-1a1ec668", "source": "https://android.googlesource.com/platform/system/bt/+/26a348a610ec277384c98f42acd841ae647d2131", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/gatt/gatt_cl.cc", "function": "gatt_process_read_by_type_rsp" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "128209036849682925507769272032220842630", "118148119298219337041890358602925579698", "100322082609158840451188941519335099218", "205891181816671458137863107350817757273", "339782928233670025478778286670126471030", "5549041135905431976777039003897884896", "231526857142627928993022467953418278079", "314515756551669587750579748008643120521" ] }, "id": "ASB-A-158833854-5c856825", "source": "https://android.googlesource.com/platform/system/bt/+/26a348a610ec277384c98f42acd841ae647d2131", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/gatt/gatt_cl.cc" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/system/bt/+/26a348a610ec277384c98f42acd841ae647d2131" ], "spl": "2020-10-01", "severity": "High", "types": [ "ID" ] }
{ "vanir_signatures": [ { "digest": { "length": 4639.0, "function_hash": "42957258101994466047224867379899158865" }, "id": "ASB-A-158833854-5e9454b6", "source": "https://android.googlesource.com/platform/system/bt/+/26a348a610ec277384c98f42acd841ae647d2131", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/gatt/gatt_cl.cc", "function": "gatt_process_read_by_type_rsp" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "128209036849682925507769272032220842630", "118148119298219337041890358602925579698", "100322082609158840451188941519335099218", "205891181816671458137863107350817757273", "339782928233670025478778286670126471030", "5549041135905431976777039003897884896", "231526857142627928993022467953418278079", "314515756551669587750579748008643120521" ] }, "id": "ASB-A-158833854-b9570689", "source": "https://android.googlesource.com/platform/system/bt/+/26a348a610ec277384c98f42acd841ae647d2131", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/gatt/gatt_cl.cc" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/system/bt/+/26a348a610ec277384c98f42acd841ae647d2131" ], "spl": "2020-10-01", "severity": "High", "types": [ "ID" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "128209036849682925507769272032220842630", "118148119298219337041890358602925579698", "100322082609158840451188941519335099218", "205891181816671458137863107350817757273", "339782928233670025478778286670126471030", "5549041135905431976777039003897884896", "231526857142627928993022467953418278079", "314515756551669587750579748008643120521" ] }, "id": "ASB-A-158833854-6de9f13c", "source": "https://android.googlesource.com/platform/system/bt/+/26a348a610ec277384c98f42acd841ae647d2131", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/gatt/gatt_cl.cc" }, "signature_type": "Line" }, { "digest": { "length": 4639.0, "function_hash": "42957258101994466047224867379899158865" }, "id": "ASB-A-158833854-d48d27c2", "source": "https://android.googlesource.com/platform/system/bt/+/26a348a610ec277384c98f42acd841ae647d2131", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/gatt/gatt_cl.cc", "function": "gatt_process_read_by_type_rsp" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/system/bt/+/26a348a610ec277384c98f42acd841ae647d2131" ], "spl": "2020-10-01", "severity": "High", "types": [ "ID" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "128209036849682925507769272032220842630", "118148119298219337041890358602925579698", "100322082609158840451188941519335099218", "205891181816671458137863107350817757273", "339782928233670025478778286670126471030", "5549041135905431976777039003897884896", "231526857142627928993022467953418278079", "314515756551669587750579748008643120521" ] }, "id": "ASB-A-158833854-31a872ba", "source": "https://android.googlesource.com/platform/system/bt/+/26a348a610ec277384c98f42acd841ae647d2131", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/gatt/gatt_cl.cc" }, "signature_type": "Line" }, { "digest": { "length": 4639.0, "function_hash": "42957258101994466047224867379899158865" }, "id": "ASB-A-158833854-a1599395", "source": "https://android.googlesource.com/platform/system/bt/+/26a348a610ec277384c98f42acd841ae647d2131", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/gatt/gatt_cl.cc", "function": "gatt_process_read_by_type_rsp" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/system/bt/+/26a348a610ec277384c98f42acd841ae647d2131" ], "spl": "2020-10-01", "severity": "High", "types": [ "ID" ] }
{ "vanir_signatures": [ { "digest": { "length": 4639.0, "function_hash": "42957258101994466047224867379899158865" }, "id": "ASB-A-158833854-14bfa661", "source": "https://android.googlesource.com/platform/system/bt/+/26a348a610ec277384c98f42acd841ae647d2131", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/gatt/gatt_cl.cc", "function": "gatt_process_read_by_type_rsp" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "128209036849682925507769272032220842630", "118148119298219337041890358602925579698", "100322082609158840451188941519335099218", "205891181816671458137863107350817757273", "339782928233670025478778286670126471030", "5549041135905431976777039003897884896", "231526857142627928993022467953418278079", "314515756551669587750579748008643120521" ] }, "id": "ASB-A-158833854-d42fb086", "source": "https://android.googlesource.com/platform/system/bt/+/26a348a610ec277384c98f42acd841ae647d2131", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/gatt/gatt_cl.cc" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/system/bt/+/26a348a610ec277384c98f42acd841ae647d2131" ], "spl": "2020-10-01", "severity": "High", "types": [ "ID" ] }