PT-2025-1031 · Google · Android

Published

2025-01-01

·

Updated

2025-01-23

·

CVE-2024-43096

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android versions prior to the January 5, 2025 patch
Description The issue is related to a missing bounds check in the build read multi rsp function of gatt sr.cc, which could lead to a possible out of bounds write. This could result in remote code execution with no additional execution privileges needed. User interaction is not required for exploitation. The vulnerability is associated with incorrect code generation management in the Android operating system.
Recommendations For Android versions prior to the January 5, 2025 patch, update devices as soon as possible with the January 5, 2025 patch to avoid remote access and data breaches. Enable auto-updates and be cautious online. As a temporary workaround, consider restricting access to the build read multi rsp function and the tGATT SR CMD until a patch is available. Avoid setting the mtu parameter to zero in the request parameters. Restrict the use of multiple invalid or controlled handles.

Fix

RCE

Memory Corruption

Code Injection

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-323850943
BDU:2025-00235
BDU:2025-00236
BDU:2025-00237
BDU:2025-00238
BDU:2025-00239
BDU:2025-00240
BDU:2025-00241
CVE-2024-43096

Affected Products

Android