MEDIUM
In bta_av_config_ind of bta_av_aact.cc, there is a possible out of bounds read due to type confusion
Published Sep 4, 2025
4.0
MEDIUMCVSS 3.1
EPSS 0.09%
Description
In bta_av_config_ind of bta_av_aact.cc, there is a possible out of bounds read due to type confusion. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected products
-
- Version 13StatusaffectedConstraints-
- Version 14StatusaffectedConstraints-
- Version 15StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner google_android
Published Sep 4, 2025
Updated Sep 4, 2025
Reserved Jun 15, 2023
Link CVE-2023-35657
CISA Vulnrichment
Updated Sep 4, 2025
ENISA EUVD
EUVD-2023-39657 Assigner google_android
Published Sep 4, 2025
Updated Sep 4, 2025
Exploited since n/a
Link EUVD-2023-39657