CVE-2023-35684Out-of-bounds Write in Packages Modules Bluetooth

Severity
8.8HIGHNVD
EPSS
0.0%
top 92.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 11

Description

In avdt_msg_asmbl of avdt_msg.cc, there is a possible out of bounds write due to an integer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

Androidplatform/packages_modules_bluetooth13-next:013-next:2023-09-01+1
CVEListV5google/android4 versions+3
NVDgoogle/android4 versions+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-4qm9-79gr-55jx: In avdt_msg_asmbl of avdt_msg2023-09-11
CVEList
CVE-2023-35684: In avdt_msg_asmbl of avdt_msg2023-09-11
OSV
CVE-2023-35684: In avdt_msg_asmbl of avdt_msg2023-09-01

📋Vendor Advisories

1
Android
CVE-2023-35684: Android Security Bulletin 2023-09-01 CVE: CVE-2023-35684 Severity: HIGH Type: EoP Affected AOSP versions: 11, 12, 12L, 13 References: A-2806336992023-09-01
CVE-2023-35684 — Out-of-bounds Write | cvebase