PT-2020-16601 · Google · Android

Published

2020-12-15

·

Updated

2020-12-15

·

CVE-2020-27024

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions Android-11
Description In the smp br state machine event function of smp br main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure triggered by a malformed Bluetooth packet, with no additional execution privileges needed. User interaction is not needed for exploitation. The Bounds Sanitizer mitigates this issue in the default configuration.
Recommendations For Android version Android-11, consider applying configuration changes to mitigate the risk of exploitation, such as enabling the Bounds Sanitizer in the default configuration. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-27024

Affected Products

Android