In BTMTryAllocateSCN of btmscn.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "229649218305656428549971312928355924069", "302020453849528639859788595298992076256", "329111539459289314853287617962020363517", "318226620072315205662574818221075035721", "100087434589779038505505906702542202188", "130280296058774809801173065708333676216", "227120603825068718216275169200270064687", "150076396632444464927396083357598623209" ] }, "id": "ASB-A-180939982-18380d56", "source": "https://android.googlesource.com/platform/system/bt/+/0d93359dbbe99da62528b236ba4a9ab92f06c6af", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/btm/btm_acl.cc" }, "signature_type": "Line" }, { "digest": { "length": 216.0, "function_hash": "170137943210695062333103982890720332686" }, "id": "ASB-A-180939982-2579a72d", "source": "https://android.googlesource.com/platform/system/bt/+/0d93359dbbe99da62528b236ba4a9ab92f06c6af", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/btm/btm_acl.cc", "function": "BTM_TryAllocateSCN" }, "signature_type": "Function" }, { "digest": { "length": 183.0, "function_hash": "34207615692176020308457833992444319540" }, "id": "ASB-A-180939982-537e823a", "source": "https://android.googlesource.com/platform/system/bt/+/0d93359dbbe99da62528b236ba4a9ab92f06c6af", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/btm/btm_acl.cc", "function": "BTM_FreeSCN" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/system/bt/+/0d93359dbbe99da62528b236ba4a9ab92f06c6af" ], "spl": "2021-07-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "229649218305656428549971312928355924069", "302020453849528639859788595298992076256", "329111539459289314853287617962020363517", "318226620072315205662574818221075035721", "100087434589779038505505906702542202188", "130280296058774809801173065708333676216", "227120603825068718216275169200270064687", "150076396632444464927396083357598623209" ] }, "id": "ASB-A-180939982-3192a4b1", "source": "https://android.googlesource.com/platform/system/bt/+/0d93359dbbe99da62528b236ba4a9ab92f06c6af", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/btm/btm_acl.cc" }, "signature_type": "Line" }, { "digest": { "length": 183.0, "function_hash": "34207615692176020308457833992444319540" }, "id": "ASB-A-180939982-69987113", "source": "https://android.googlesource.com/platform/system/bt/+/0d93359dbbe99da62528b236ba4a9ab92f06c6af", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/btm/btm_acl.cc", "function": "BTM_FreeSCN" }, "signature_type": "Function" }, { "digest": { "length": 216.0, "function_hash": "170137943210695062333103982890720332686" }, "id": "ASB-A-180939982-b54b0eae", "source": "https://android.googlesource.com/platform/system/bt/+/0d93359dbbe99da62528b236ba4a9ab92f06c6af", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/btm/btm_acl.cc", "function": "BTM_TryAllocateSCN" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/system/bt/+/0d93359dbbe99da62528b236ba4a9ab92f06c6af" ], "spl": "2021-07-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 216.0, "function_hash": "170137943210695062333103982890720332686" }, "id": "ASB-A-180939982-645e8ba1", "source": "https://android.googlesource.com/platform/system/bt/+/0d93359dbbe99da62528b236ba4a9ab92f06c6af", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/btm/btm_acl.cc", "function": "BTM_TryAllocateSCN" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "229649218305656428549971312928355924069", "302020453849528639859788595298992076256", "329111539459289314853287617962020363517", "318226620072315205662574818221075035721", "100087434589779038505505906702542202188", "130280296058774809801173065708333676216", "227120603825068718216275169200270064687", "150076396632444464927396083357598623209" ] }, "id": "ASB-A-180939982-8722f9a6", "source": "https://android.googlesource.com/platform/system/bt/+/0d93359dbbe99da62528b236ba4a9ab92f06c6af", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/btm/btm_acl.cc" }, "signature_type": "Line" }, { "digest": { "length": 183.0, "function_hash": "34207615692176020308457833992444319540" }, "id": "ASB-A-180939982-a8459a99", "source": "https://android.googlesource.com/platform/system/bt/+/0d93359dbbe99da62528b236ba4a9ab92f06c6af", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/btm/btm_acl.cc", "function": "BTM_FreeSCN" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/system/bt/+/0d93359dbbe99da62528b236ba4a9ab92f06c6af" ], "spl": "2021-07-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 183.0, "function_hash": "34207615692176020308457833992444319540" }, "id": "ASB-A-180939982-1aaa3bb6", "source": "https://android.googlesource.com/platform/system/bt/+/0d93359dbbe99da62528b236ba4a9ab92f06c6af", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/btm/btm_acl.cc", "function": "BTM_FreeSCN" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "229649218305656428549971312928355924069", "302020453849528639859788595298992076256", "329111539459289314853287617962020363517", "318226620072315205662574818221075035721", "100087434589779038505505906702542202188", "130280296058774809801173065708333676216", "227120603825068718216275169200270064687", "150076396632444464927396083357598623209" ] }, "id": "ASB-A-180939982-451c7e7d", "source": "https://android.googlesource.com/platform/system/bt/+/0d93359dbbe99da62528b236ba4a9ab92f06c6af", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/btm/btm_acl.cc" }, "signature_type": "Line" }, { "digest": { "length": 216.0, "function_hash": "170137943210695062333103982890720332686" }, "id": "ASB-A-180939982-4d888ce6", "source": "https://android.googlesource.com/platform/system/bt/+/0d93359dbbe99da62528b236ba4a9ab92f06c6af", "deprecated": false, "signature_version": "v1", "target": { "file": "stack/btm/btm_acl.cc", "function": "BTM_TryAllocateSCN" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/system/bt/+/0d93359dbbe99da62528b236ba4a9ab92f06c6af" ], "spl": "2021-07-01", "severity": "High", "types": [ "EoP" ] }