Commits on Source (5)
-
Brian Delwiche authored
This flag has been soaked for more than a month and is ready for removal. This is a cherry-pick of ag/30363401 -- the 25Q2 branch was cut with the flag still present and we need to remove that flag to close. Bug: 356201480 Flag: EXEMPT flag removal Test: m libbluetooth Tag: #security Ignore-AOSP-First: Security Change-Id: I31d47316748515fb44d729ba14946f98420afb36 (cherry picked from commit 769caf391c6055c6f9db945b71d96b2f01c8799c)
-
Brian Delwiche authored
Flag has been in Nextfood for nine weeks per Gantry and should be safe to remove. This is a cherry-pick of the reland version and is required because the 25Q2 branch was cut after the fix was in place but before the flag was removed. Test: mmm packages/modules/Bluetooth Flag: EXEMPT removing flag com.android.bluetooth.flags.bonded_device_smp_failure_handling Bug: 385181815 Change-Id: I2cc107a3de1b84cd45af13209ed45cfcec5a5216 (cherry picked from commit 77cc20f000ef4e69fdc1297f6f99e9b379ab5733) DISABLE_TOPIC_PROTECTOR
-
Brian Delwiche authored
In SendPacketToPeer of acl_arbiter.cc, a buffer length is logged in one case after an intermediate call may free the buffer, leading to use after free. Log instead from the buffer's source, which has not been freed at this point in the code. Bug: 406785684 Flag: EXEMPT obvious logic fix Test: m libbluetooth Test: researcher POC Tag: #security Change-Id: Idd13399c24399d01bcd668a4b779ef1980273691 (cherry picked from commit 243d7484e59730c522640b616445b2747b3062e5)
-
Brian Delwiche authored
-
Michael Bestas authored
Merge branch 'android16-security-release' of https://android.googlesource.com/platform/packages/modules/Bluetooth into lineage-23.0 * 'android16-security-release' of https://android.googlesource.com/platform/packages/modules/Bluetooth: Fix use after free in acl_arbiter Remove flag bonded_device_smp_failure_handling Remove flag btsec_check_valid_discovery_database Change-Id: Ibd306a11c26c812da55557ca29603be91e2c17aa