• CVE-2023-21108

发布时间: 2023年6月26日

修改时间: 2023年6月26日

概要

In sdpu_build_uuid_seq of sdp_discovery.cc, there is a possible out of bounds write due to a use after free. This could lead to remote code execution over Bluetooth, if HFP support is enabled, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-239414876

CVSS v3 指标

NVD openEuler
CVSS评分 8.8 8.8
Attack Vector Adjacent Adjacent
Attack Complexity Low Low
Privileges Required None None
User Interaction None None
Scope Unchanged Unchanged
Confidentiality High High
Integrity High High
Availability High High

安全公告

公告名 概要 发布时间
KylinSec-SA-2023-1467 In sdpu_build_uuid_seq of sdp_discovery.cc, there is a possible out of bounds write due to a use after free. This could lead to remote code execution over Bluetooth, if HFP support is enabled, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-239414876 2023年6月26日

影响产品

产品 状态
KY3.4-4A bluez Unaffected
KY3.4-5 bluez Unaffected
KY3.5.1 bluez Unaffected
KY3.5.2 bluez Unaffected