1. 3c1471d Merge branch 'security-aosp-pi-release' into int/p/fp2 by Maarten Derks · 2 years, 5 months ago int/p/fp2 rel/p/fp2/21.12.0-rel rel/p/fp2/21.12.0-rel.1
  2. 434d551 Merge cherrypicks of [16009369, 16012240, 16012308, 16012309, 16012331, 16012215, 16012281, 16012282, 16012283, 16012332, 16012284] into security-aosp-pi-release by Android Build Coastguard Worker · 2 years, 7 months ago
  3. 8d09281 osi: Prevent memory allocations with MSB set by Chris Manton · 2 years, 8 months ago
  4. a847bb2 Merge the 2021-09-05 SPL branch from AOSP-Partner by Maarten Derks · 2 years, 9 months ago rel/p/fp2/21.08.1-rel rel/p/fp2/21.10.0-rel rel/p/fp2/21.08.1-rel.0 rel/p/fp2/21.10.0-rel.2
  5. 3c64016 Merge the 2021-08-05 SPL branch from AOSP-Partner by Luca Weiss · 2 years, 10 months ago
  6. 0dd9562 Merge cherrypicks of [15151696, 15151717, 15151893, 15151895, 15151897, 15151898, 15150909, 15151854, 15151855, 15151385, 15151702, 15151705, 15151707] into security-aosp-pi-release by Android Build Coastguard Worker · 2 years, 11 months ago
  7. d762055 SMP: Reject pairing if public_key.x match by Hansong Zhang · 3 years ago
  8. 848bb18 Merge cherrypicks of [14553530, 14552439, 14553531, 14553532, 14554542, 14551981, 14553644, 14553645, 14554582, 14554583, 14554584, 14553501, 14554602, 14554603, 14554604, 14552580, 14553646, 14553647] into security-aosp-pi-release by android-build-team Robot · 3 years ago
  9. e7cfd02 Fix memory overflow. by Richard Smith · 3 years, 3 months ago
  10. 8812377 Merge the 2021-06-05 SPL branch from AOSP-Partner by Karsten Tausche · 3 years ago rel/p/fp2/21.05.0-rel rel/p/fp2/21.05.0-rel.1
  11. e86182d Merge cherrypicks of [14126781, 14126782, 14127202, 14128466, 14127516, 14128057, 14127204, 14128747, 14128708, 14128059, 14128686, 14128127, 14128507, 14128809, 14128810, 14128811, 14128812] into security-aosp-pi-release by android-build-team Robot · 3 years, 1 month ago
  12. a26e210 RESTRICT AUTOMERGE Contain avrc_ctrl_pars_vendor_cmd OOB write by Chris Manton · 3 years, 2 months ago
  13. 943149c AVRCP: pass bdaddr by value when use SdpCb by Chienyuan · 3 years, 3 months ago
  14. 828c90d smp: Use SMP_TRACE_WARNING by Myles Watson · 3 years, 2 months ago
  15. 90d1908 smp: Reject pairing if the public keys match by Myles Watson · 3 years, 3 months ago
  16. e96c52f Merge the 2021-03-05 SPL branch from AOSP-Partner by Karsten Tausche · 3 years, 2 months ago rel/p/fp2/21.03.0-rel rel/p/fp2/21.03.0-rel.1 rel/p/fp2/21.03.0-rel.2
  17. 7d5ca7b avrcp: Ignore AVCT commands that are too long by Myles Watson · 3 years, 3 months ago
  18. 7f765b0 DO NOT MERGE Add mutex for std::map in btif_av.cc by Chienyuan · 3 years, 4 months ago
  19. 507ae79 AVRCP: Use calloc to zero reserved fields by Myles Watson · 3 years, 5 months ago
  20. 4969f94 avrc_copy_packet: Zero initialize packet by Hansong Zhang · 3 years, 5 months ago
  21. 3e963f8 Legacy pairing: Reject device with same BD_ADDR by Hansong Zhang · 3 years, 5 months ago
  22. c2fd12e Merge the 2021-02-05 SPL branch from AOSP-Partner by Karsten Tausche · 3 years, 4 months ago rel/p/fp2/21.01.0-rel 21.01.0-rel.0 rel/p/fp2/21.01.0-rel.1
  23. 12b0b88 SDP: Only start discovery once by Myles Watson · 3 years, 5 months ago
  24. 82eb91b ACL: Drop broadcasts by Myles Watson · 3 years, 7 months ago
  25. 9d40836 Fix potential OOB write in libbluetooth by Ted Wang · 3 years, 7 months ago
  26. 779fc08 Fix a security issue in sdp_server.cc by Hansong Zhang · 3 years, 7 months ago
  27. 9b39d6b Check Classic key before cross-key derivation by Chen Chen · 3 years, 8 months ago
  28. 231987a Merge the 2020-10-05 SPL branch from AOSP-Partner by Karsten Tausche · 3 years, 7 months ago rel/p/fp2/20.10.1-beta rel/p/fp2/20.12.0-beta 20.10.1-beta.0 20.12.0-beta.0 20.12.0-beta.1
  29. 232ab7e Merge the android-9.0.0_r60 release tag Android 9.0.0 release 60 by Karsten Tausche · 3 years, 7 months ago
  30. b32e3b3 Send a response to an smp security request depending on the callback event by Rahul Sabnis · 3 years, 9 months ago
  31. c6e7fb8 Return after removing sample LTK device by li-wei.cheng · 4 years, 4 months ago
  32. 73dea2b Check whether local device is an ATV device to determine whether to show by Rahul Sabnis · 3 years, 10 months ago
  33. 044ea0e Shows a consent dialog on the local device when pairing a bluetooth low by Rahul Sabnis · 3 years, 11 months ago
  34. 5a827a3 Fix possible OOB when receive gatt read type response data by weichinweng · 3 years, 10 months ago
  35. 2f6275a Merge the android-9.0.0_r56 release tag Android 9.0.0 release 56 by Karsten Tausche · 3 years, 11 months ago
  36. df2c79e Remove pairing on incoming bond request by Myles Watson · 4 years ago
  37. eae606a Enable bitpool sanity checks by Joseph Pirozzo · 4 years ago
  38. 9991038 Merge the 2020-05-05 SPL branch from AOSP-Partner by Karsten Tausche · 4 years, 1 month ago
  39. f2f81ad Merge the android-9.0.0_r55 release tag Android 9.0.0 Release 55 (6197209) by Karsten Tausche · 4 years, 1 month ago
  40. 73c22e6 Fix potential stack overflow caused by integer overflow by Jakub Pawlowski · 4 years, 2 months ago
  41. f46a336 GattServcer: Check invalid offset by Hansong Zhang · 4 years, 3 months ago
  42. 8355edc AAC Decoder: Use osi_free() to free buffers allocated by osi_malloc() by Hansong Zhang · 4 years, 3 months ago
  43. 93fb6ed Add changes for the initial bringup of the bluetooth stack by Vivekbalachandar Marisamy · 4 years, 6 months ago
  44. c20f248 SDP: add return after SDP disconnection by Zongheng Wang · 4 years, 6 months ago
  45. 1d788d2 Fix potential OOB write in btm_read_remote_ext_features_complete by Ted Wang · 4 years, 6 months ago
  46. abc3023 GAP: Correct the continuous pkt length in l2cap by Venkata Jagadeesh Garaga · 5 years ago
  47. 3cea33e [system][bt] fix -Wdangling-gsl by Nick Desaulniers · 4 years, 7 months ago
  48. 45bdb51 JustWorks: Auto-accept only incoming temporary pairing. by Martin Brabham · 5 years ago
  49. a0d9335 Fix read out of bounds in BtifAvEvent::DeepCopy by Jakub Pawlowski · 4 years, 8 months ago
  50. 8a42593 Revert "DO NOT MERGE: btif: require pairing dialog for JustWorks SSP" by Martin Brabham · 5 years ago
  51. 8408658 SDP: Disconnect when there is a bad length by Zongheng Wang · 4 years, 9 months ago
  52. babcc90 Use memcpy instead of casting to convert device_class to int by Rahul Sabnis · 4 years, 9 months ago
  53. b158fe6 SDP: disconnect if sdp_copy_raw_data fails by Zongheng Wang · 4 years, 9 months ago
  54. 627f104 DO NOT MERGE: btif: require pairing dialog for JustWorks SSP by Martin Brabham · 5 years ago
  55. d79424a DO NOT MERGE Store BLE keys using the address from the ble_auth_cmpl_evt by Ugo Yu · 4 years, 10 months ago
  56. ce061b3 DO NOT MERGE Separate SDP procedure from bonding state (1/2) by Ugo Yu · 5 years ago
  57. 6130265 Revert "DO NOT MERGE Separate SDP procedure from bonding state (1/2)" by Arjun Garg · 4 years, 10 months ago
  58. a950098 DO NOT MERGE Fix for Bluetooth connection being dropped after HCI Read Encryption Key Size by Jakub Pawlowski · 5 years ago
  59. 12df1a2 DO NOT MERGE Separate SDP procedure from bonding state (1/2) by Ugo Yu · 5 years ago
  60. 23c8efe DO NOT MERGE: osi: Offload mutex pointer to local scope by Martin Brabham · 5 years ago
  61. b78df74 Fix potential OOB read in sdpu_get_len_from_type by Ted Wang · 5 years ago
  62. 859dc4b DO NOT MERGE Don't persist bonds using sample LTK by Jakub Pawlowski · 5 years ago
  63. 41453cf DO NOT MERGE Log encryption key size by Jack He · 5 years ago
  64. 5396002 DO NOT MERGE Drop Bluetooth connection with weak encryption key by Jakub Pawlowski · 5 years ago
  65. bd58952 DO NOT MERGE: Use a weak pointer to deliver updates to AVRCP devices. by Ajay Panicker · 5 years ago
  66. e3f5d88 Revert "DO NOT MERGE Separate SDP procedure from bonding state (1/2)" by JP Sugarbroad · 5 years ago
  67. 5cd56bc resolve merge conflicts of ec78d74706c3e81f91eee53e3d9f959f66e5d77f to pi-dev by Hansong Zhang · 5 years ago
  68. 583a701 DO NOT MERGE Separate SDP procedure from bonding state (1/2) by Ugo Yu · 6 years ago
  69. 9757501 btm_proc_smp_cback: Don't access p_dev_rec if freed by Hansong Zhang · 5 years ago
  70. be319c6 btm_ble_multi_adv: Check data length in HCI interface by Hansong Zhang · 5 years ago
  71. 39545b9 DO NOT MERGE A security fix to check buffer length in l2c_lcc_proc_pdu by Stanley Tng · 5 years ago
  72. bf4354a Add OOB check in avrc_pars_browse_rsp by Ugo Yu · 6 years ago
  73. 1ffc001 Fix buffer overflow in btif_dm_data_copy by Jakub Pawlowski · 5 years ago
  74. 31e987d Fix potential usage of freed memory in btif_hl_proc_sdp_query_cfm by Jakub Pawlowski · 5 years ago
  75. e83b6bf Revert "Fix OOB in avrc_pars_browse_rsp" by JP Sugarbroad · 5 years ago
  76. 4dbcf78 SDP: Check p_end in save_attr_seq and add_attr by Myles Watson · 6 years ago
  77. 751fa58 Fix OOB in avrc_pars_browse_rsp by Ugo Yu · 6 years ago
  78. 45f184d Fix possible OOB when AVDT data channel recive ACL data by Ugo Yu · 6 years ago
  79. 91bc82b HFP: Check AT command buffer boundary during parsing by Chienyuan · 6 years ago
  80. 9587a3b MCAP: Check response length in mca_ccb_hdl_rsp by Myles Watson · 6 years ago
  81. 12bfecf HH: Check parameter length in bta_hh_ctrl_dat_act by Myles Watson · 6 years ago
  82. dffadff Fix possible OOB read by Jakub Pawlowski · 6 years ago
  83. 9b8b65d HIDD: Check descriptor length and increase buffer by Hansong Zhang · 6 years ago
  84. c865871 Check SDU lower bound before allocate p_data by Ugo Yu · 6 years ago
  85. b64d43e bta: Pass the correct UUID array size in bta_ag_do_disc by Myles Watson · 6 years ago
  86. 9656ad0 Check AVRCP data length when parsing inside avrc_ctrl_pars_vendor_rsp() by Pavlin Radoslavov · 6 years ago
  87. ec9a5ca HID Device: Fix OOB in register_app by Hansong Zhang · 6 years ago
  88. d631653 Check data length when parsing AVRCP vendor specific command responses by Pavlin Radoslavov · 6 years ago
  89. 9b72e41 Check remaining frame length in rfc_process_mx_message by Hansong Zhang · 6 years ago
  90. e845a59 Fix a wrong check in rfc_parse_data by Hansong Zhang · 6 years ago
  91. e9cb25b Add bound check for rfc_parse_data by Hansong Zhang · 6 years ago
  92. 7709a4e Checks the SMP length to fix OOB read by Cheney Ni · 6 years ago
  93. e5dbf9f Add packet length check in smp_proc_master_id by Ugo Yu · 6 years ago
  94. 2df0028 Add missing AVRCP message length checks inside avrc_msg_cback by Pavlin Radoslavov · 6 years ago
  95. 240a97f Add packet length checks in mca_ccb_hdl_req by Cheney Ni · 6 years ago
  96. 2eb5b0b Check packet length in bta_av_proc_meta_cmd by Chienyuan · 6 years ago
  97. efca084 Fix OOB read in avrc_ctrl_pars_vendor_rsp by Hansong Zhang · 6 years ago
  98. e08e28a Fix copy length calculation in sdp_copy_raw_data by Jakub Pawlowski · 6 years ago
  99. 99908dc Fix OOB read in process_l2cap_cmd by Hansong Zhang · 6 years ago
  100. 93dc1e3 SDP: return error on offset bigger than atribute length by Jakub Pawlowski · 6 years ago