{ "schema_version": "1.4.0", "id": "GHSA-r2pg-5xw6-p694", "modified": "2022-05-24T17:36:28Z", "published": "2022-05-24T17:36:28Z", "aliases": [ "CVE-2020-27024" ], "details": "In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure triggered by a malformed Bluetooth packet, with no additional execution privileges needed. User interaction is not needed for exploitation. Bounds Sanitizer mitigates this in the default configuration.Product: AndroidVersions: Android-11Android ID: A-162327732", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-27024" }, { "type": "WEB", "url": "https://source.android.com/security/bulletin/pixel/2020-12-01" } ], "database_specific": { "cwe_ids": [ "CWE-125" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-12-15T16:15:00Z" } }