CVE-2023-21280Uncontrolled Resource Consumption in Frameworks Base

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 14
Latest updateAug 15

Description

In setMediaButtonBroadcastReceiver of MediaSessionRecord.java, there is a possible permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

Androidplatform/frameworks_base13-next:013-next:2023-08-01+3
CVEListV5google/android12, 12L, 13+2
NVDgoogle/android12.0, 12.1, 13.0+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6mv9-jvm8-g7rq: In setMediaButtonBroadcastReceiver of MediaSessionRecord2023-08-15
OSV
CVE-2023-21280: In setMediaButtonBroadcastReceiver of MediaSessionRecord2023-08-01

📋Vendor Advisories

1
Android
CVE-2023-21280: Android Security Bulletin 2023-08-01 CVE: CVE-2023-21280 Severity: HIGH Type: DoS Affected AOSP versions: 12, 12L, 13 References: A-2700493792023-08-01