Skip to content

Conversation

@gowthambabu92
Copy link
Contributor

@gowthambabu92 gowthambabu92 commented Mar 6, 2025

Any apps can get Bluetooth device picker activity and enable always discoverable and connectable scanning, which is vulnerable as anyone can connect to it.

Fixes CVE_2022_20429 vulnerability issue by allowing only settings and system UI packages to turn on always discoverable BT scanning.

Cherry picked from
https://cs.android.com/android/_/android/platform/packages/apps/Car/Settings/+/7adb8ff6d30a1ab8f83c7b1fbddf04d76cfd9642

Tests-done:

  1. Flash AAOS
  2. BT on success
  3. run android.security.cts.CVE_2022_20429.CVE_2022_20429#testPocCVE_2022_20429
  4. Test pass

Tracked-On: OAM-130036

@sysopenci
Copy link

Program name for this pr is not compatable with other dependent prs, for more details please check tracked_on

Any apps can get Bluetooth device picker activity and enable
always discoverable and connectable scanning, which is vulnerable
as anyone can connect to it.

Fixes CVE_2022_20429 vulnerability issue by allowing only settings and
system UI packages to turn on always discoverable BT scanning.

Cherry picked from
https://cs.android.com/android/_/android/platform/packages/apps/Car/Settings/+/7adb8ff6d30a1ab8f83c7b1fbddf04d76cfd9642

Tests-done:
1. Flash AAOS
2. BT on success
3. run android.security.cts.CVE_2022_20429.CVE_2022_20429#testPocCVE_2022_20429
4. Test pass

Tracked-On: OAM-130036
Signed-off-by: Gowtham Anandha Babu <gowtham.anandha.babu@intel.com>
@sysopenci
Copy link

Android CI has started Engineering Build for this issue ,Please check the linked Tracked-On issue/Android CI Web for more details.

Copy link
Contributor

@balajim001 balajim001 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@sysopenci
Copy link

Android CI has started Engineering Build for this issue ,Please check the linked Tracked-On issue/Android CI Web for more details.

@sysopenci
Copy link

FAILURE: Android CI has completed Engineering Build for this issue.Please check the linked Tracked-On issue/Android CI Web for more details.

@sysopenci sysopenci added Engineering Build Failed and removed Engineering Build Not Started Engineering Build Not Started labels Mar 10, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants