In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error in the code. This could lead to local escalation of privilege that fails to remove the persistent dot with no additional execution privileges needed. User interaction is not needed for exploitation.
References
Link | Resource |
---|---|
https://android.googlesource.com/platform/frameworks/base/+/d6f7188773409c8f5ad5fc7d3eea5b1751439e26 | Mailing List Patch |
https://source.android.com/security/bulletin/2024-02-01 | Patch Vendor Advisory |
https://android.googlesource.com/platform/frameworks/base/+/d6f7188773409c8f5ad5fc7d3eea5b1751439e26 | Mailing List Patch |
https://source.android.com/security/bulletin/2024-02-01 | Patch Vendor Advisory |
Configurations
History
16 Dec 2024, 14:47
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* | |
CWE | CWE-362 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.0 |
First Time |
Google android
|
|
References | () https://android.googlesource.com/platform/frameworks/base/+/d6f7188773409c8f5ad5fc7d3eea5b1751439e26 - Mailing List, Patch | |
References | () https://source.android.com/security/bulletin/2024-02-01 - Patch, Vendor Advisory |
21 Nov 2024, 08:45
Type | Values Removed | Values Added |
---|---|---|
References | () https://android.googlesource.com/platform/frameworks/base/+/d6f7188773409c8f5ad5fc7d3eea5b1751439e26 - | |
References | () https://source.android.com/security/bulletin/2024-02-01 - |
26 Aug 2024, 17:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.4 |
16 Feb 2024, 13:37
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
16 Feb 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-16 02:15
Updated : 2025-03-28 16:15
NVD link : CVE-2024-0041
Mitre link : CVE-2024-0041
CVE.ORG link : CVE-2024-0041
JSON object : View
Products Affected
- android
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')