CVE-2024-0022
published 2024-05-07CVE-2024-0022: In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to…
PriorityP426medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.10%
1.3th percentile
In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 13:0 < 13:2024-04-01 | 13:2024-04-01 |
| platform | frameworks_base | >= 14-next:0 < 14-next:2024-04-01 | 14-next:2024-04-01 |
| platform | frameworks_base | >= 14:0 < 14:2024-04-01 | 14:2024-04-01 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: gpio: pca953x: fix pca953x_irq_bus_sync_unlock race
vendor_redhat·2024-08-08·CVSS 4.7
CVE-2024-42253 [MEDIUM] CWE-667 kernel: gpio: pca953x: fix pca953x_irq_bus_sync_unlock race
kernel: gpio: pca953x: fix pca953x_irq_bus_sync_unlock race
In the Linux kernel, the following vulnerability has been resolved:
gpio: pca953x: fix pca953x_irq_bus_sync_unlock race
Ensure that `i2c_lock' is held when setting interrupt latch and mask in
pca953x_irq_bus_sync_unlock() in order to avoid races.
The other (non-probe) call site pca953x_gpio_set_multiple() ensures the
lock is held before calling pca953x_write_regs().
The problem occurred when a request raced against irq_bus_sync_unlock()
approximately once per thousand reboots on an i.MX8MP based system.
* Normal case
0-0022: write register AI|3a {03,02,00,00,01} Input latch P0
0-0022: write register AI|49 {fc,fd,ff,ff,fe} Interrupt mask P0
0-0022: write register AI|08 {ff,00,00,00,00} Output P3
0-0022: write register AI|12 {fc,00
Android
CVE-2024-0022: Android Security Bulletin 2024-04-01
CVE: CVE-2024-0022
Severity: HIGH
Type: ID
Affected AOSP versions: 13, 14
References: A-298635078
vendor_android·2024-04-01·CVSS 5.5
CVE-2024-0022 [MEDIUM] CVE-2024-0022: Android Security Bulletin 2024-04-01
CVE: CVE-2024-0022
Severity: HIGH
Type: ID
Affected AOSP versions: 13, 14
References: A-298635078
Android Security Bulletin 2024-04-01
CVE: CVE-2024-0022
Severity: HIGH
Type: ID
Affected AOSP versions: 13, 14
References: A-298635078
GHSA
GHSA-gvjh-r2g7-mjgx: In multiple functions of CompanionDeviceManagerService
ghsa_unreviewed·2024-05-07
CVE-2024-0022 [MEDIUM] CWE-20 GHSA-gvjh-r2g7-mjgx: In multiple functions of CompanionDeviceManagerService
In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2024-0022: In multiple functions of CompanionDeviceManagerService
osv·2024-04-01
CVE-2024-0022 CVE-2024-0022: In multiple functions of CompanionDeviceManagerService
In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://android.googlesource.com/platform/frameworks/base/+/bdf1cce569c9700965ff6baee8efd3fb1e8269e8https://source.android.com/security/bulletin/2024-04-01https://android.googlesource.com/platform/frameworks/base/+/bdf1cce569c9700965ff6baee8efd3fb1e8269e8https://source.android.com/security/bulletin/2024-04-01
2024-05-07
Published