CVE-2023-40129: Buffer Overflow
Published Oct 2, 2023
·Updated
In buildreadmultirsp of gattsr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
4 affected components
Google Android=12.0
Google Android=12.1
Google Android=13.0
Google Android
Remediation
Patch Available
Event History
Oct 2, 2023
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Oct 27, 2023
CVE Published
via MITRE·08:22 PM
Data Sourced
via MITRE·08:22 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-40129?
The severity of CVE-2023-40129 is critical.
2
How does CVE-2023-40129 affect Google Android?
CVE-2023-40129 affects Google Android versions 12.0, 12.1, and 13.0.
3
What is the vulnerability type of CVE-2023-40129?
CVE-2023-40129 is a heap buffer overflow vulnerability.
4
Is user interaction required for exploitation of CVE-2023-40129?
No, user interaction is not needed for exploitation of CVE-2023-40129.
5
How can I fix CVE-2023-40129?
To fix CVE-2023-40129, you should apply the security patches provided by Google for affected Android versions.