Android Bluetooth Stack Denial-of-Service Vulnerability
Vulnerability
A denial-of-service vulnerability has been identified in the Android Bluetooth stack, specifically within the 'build_read_multi_rsp' function of 'gatt_sr.cc'. This issue arises from a logic error, which could be exploited to cause a remote (proximal/adjacent) denial-of-service condition. The vulnerability does not require any additional execution privileges and can be exploited without user interaction.
Impact
Exploitation of this vulnerability leads to a remote (proximal/adjacent) denial-of-service condition, causing the affected device to become unresponsive or unavailable.
Remediation
Users can update their devices to the January 2025 security patch level to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
