{"id":"PUB-A-255305114","details":"In btm_ble_process_periodic_adv_sync_lost_evt of ble_scanner_hci_interface.cc , there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-255305114","CVE-2023-20991"],"modified":"2026-06-01T15:55:42.428303297Z","published":"2023-06-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2023-06-01"}],"affected":[{"package":{"name":"platform/packages/modules/Bluetooth","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13-next:0"},{"fixed":"13-next:2023-06-01"}]}],"versions":["13-next"],"ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/modules/Bluetooth/+/6d0884df95f251977b8ffbca912b90ebfbcb83d2"],"types":["ID"],"vanir_signatures":[{"signature_type":"Line","digest":{"threshold":0.9,"line_hashes":["126293545435270076367963561081937909340","235988437675959267100525130936193460565","93385601713951595456171969397712910026"]},"id":"PUB-A-255305114-44964580","target":{"file":"system/stack/btm/ble_scanner_hci_interface.cc"},"source":"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/6d0884df95f251977b8ffbca912b90ebfbcb83d2","deprecated":false,"signature_version":"v1"},{"source":"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/6d0884df95f251977b8ffbca912b90ebfbcb83d2","signature_version":"v1","signature_type":"Function","target":{"file":"system/stack/btm/ble_scanner_hci_interface.cc","function":"btm_ble_process_periodic_adv_sync_lost_evt"},"id":"PUB-A-255305114-b11f0acb","deprecated":false,"digest":{"length":241,"function_hash":"235667980479841068112594725593059873565"}}],"spl":"2023-06-01","severity":"Moderate"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/PUB-A-255305114.json"}},{"package":{"name":"platform/packages/modules/Bluetooth","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13:0"},{"fixed":"13:2023-06-01"}]}],"versions":["13"],"ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/modules/Bluetooth/+/85188d000ae001f7ec4517a7401b7c54820d88a1"],"types":["ID"],"vanir_signatures":[{"signature_type":"Function","digest":{"length":241,"function_hash":"235667980479841068112594725593059873565"},"id":"PUB-A-255305114-3667a2fc","target":{"file":"system/stack/btm/ble_scanner_hci_interface.cc","function":"btm_ble_process_periodic_adv_sync_lost_evt"},"source":"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/85188d000ae001f7ec4517a7401b7c54820d88a1","deprecated":false,"signature_version":"v1"},{"signature_type":"Line","digest":{"threshold":0.9,"line_hashes":["126293545435270076367963561081937909340","235988437675959267100525130936193460565","93385601713951595456171969397712910026"]},"id":"PUB-A-255305114-83ccf124","target":{"file":"system/stack/btm/ble_scanner_hci_interface.cc"},"source":"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/85188d000ae001f7ec4517a7401b7c54820d88a1","deprecated":false,"signature_version":"v1"}],"spl":"2023-06-01","severity":"Moderate"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/PUB-A-255305114.json"}}],"schema_version":"1.7.5"}