{"id":"PUB-A-260568750","details":"In on_iso_link_quality_read of btm_iso_impl.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-260568750","CVE-2023-20992"],"modified":"2026-04-03T15:37:31.002635Z","published":"2023-06-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2023-06-01"}],"affected":[{"package":{"name":"platform/packages/modules/Bluetooth","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13-next:0"},{"fixed":"13-next:2023-06-01"}]}],"versions":["13-next"],"ecosystem_specific":{"types":["ID"],"vanir_signatures":[{"id":"PUB-A-260568750-d5172d63","target":{"file":"system/stack/btm/btm_iso_impl.h"},"digest":{"line_hashes":["336182745763625551841039275102296750561","115480141108283230814474971520204765480","42238014775519316689335802152380446620"],"threshold":0.9},"source":"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/6ee00faaec12f0631c490cc1cca5f645c617aff0","signature_version":"v1","signature_type":"Line","deprecated":false}],"severity":"Moderate","fixes":["https://android.googlesource.com/platform/packages/modules/Bluetooth/+/6ee00faaec12f0631c490cc1cca5f645c617aff0"],"spl":"2023-06-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/PUB-A-260568750.json"}},{"package":{"name":"platform/packages/modules/Bluetooth","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13:0"},{"fixed":"13:2023-06-01"}]}],"versions":["13"],"ecosystem_specific":{"types":["ID"],"vanir_signatures":[{"id":"PUB-A-260568750-42714bb0","target":{"file":"system/stack/btm/btm_iso_impl.h"},"digest":{"line_hashes":["336182745763625551841039275102296750561","115480141108283230814474971520204765480","42238014775519316689335802152380446620"],"threshold":0.9},"source":"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/f7679c19e64e23697df81d14d085c94b5af01eed","signature_version":"v1","signature_type":"Line","deprecated":false}],"severity":"Moderate","fixes":["https://android.googlesource.com/platform/packages/modules/Bluetooth/+/f7679c19e64e23697df81d14d085c94b5af01eed"],"spl":"2023-06-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/PUB-A-260568750.json"}}],"schema_version":"1.7.5"}