Description
In sdpu_build_uuid_seq of sdp_discovery.cc, there is a possible out of bounds write due to a use after free. This could lead to remote code execution over Bluetooth, if HFP support is enabled, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-239414876
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-25276 | In sdpu_build_uuid_seq of sdp_discovery.cc, there is a possible out of bounds write due to a use after free. This could lead to remote code execution over Bluetooth, if HFP support is enabled, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-239414876 |
References
| Link | Providers |
|---|---|
| https://source.android.com/security/bulletin/2023-06-01 |
|
History
No history.
Status: PUBLISHED
Assigner: google_android
Published:
Updated: 2024-08-02T09:28:25.833Z
Reserved: 2022-11-03T00:00:00.000Z
Link: CVE-2023-21108
No data.
Status : Modified
Published: 2023-06-15T19:15:09.423
Modified: 2024-11-21T07:42:10.687
Link: CVE-2023-21108
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD