Описание
In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Одно из
EPSS
8 High
CVSS3
Дефекты
Связанные уязвимости
In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Уязвимость сценария l2c_fcr_clone_buf of l2c_fcr.cc операционных систем Android, позволяющая нарушителю повысить свои привилегии
EPSS
8 High
CVSS3