First published: Mon Apr 01 2024(Updated: )
In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =12.0 | |
Android | =12.1 | |
Android | =13.0 | |
Android | =14.0 |
https://android.googlesource.com/platform/frameworks/base/+/a8fb9fe93efdebc4145e00934f42c91742f328de
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0026 has a severity classification of moderate, indicating potential impact on system availability.
To address CVE-2024-0026, updating impacted Android devices to the latest version that includes the security patch is recommended.
CVE-2024-0026 affects Google Android versions 12.0, 12.1, 13.0, and 14.0.
Yes, CVE-2024-0026 can be exploited locally without any user interaction.
CVE-2024-0026 can lead to a persistent denial of service due to resource exhaustion on affected Android devices.