CVE-2024-0041Race Condition in Frameworks Base

CWE-362Race Condition4 documents4 sources
Severity
7.0HIGHNVD
EPSS
0.0%
top 94.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 16

Description

In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error in the code. This could lead to local escalation of privilege that fails to remove the persistent dot with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages4 packages

Androidplatform/frameworks_base14-next:014-next:2024-02-01+1
CVEListV5google/android14
NVDgoogle/android14.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6w8c-45mh-9rvm: In removePersistentDot of SystemStatusAnimationSchedulerImpl2024-02-16
OSV
CVE-2024-0041: In removePersistentDot of SystemStatusAnimationSchedulerImpl2024-02-01

📋Vendor Advisories

1
Android
CVE-2024-0041: Android Security Bulletin 2024-02-01 CVE: CVE-2024-0041 Severity: HIGH Type: EoP Affected AOSP versions: 14 References: A-3007411862024-02-01