CVE Vulnerabilities

CVE-2022-20476

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Dec 13, 2022 | Modified: Apr 22, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In setEnabledSetting of PackageManager.java, there is a possible way to get the device into an infinite reboot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-240936919

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle10.0 (including)10.0 (including)
AndroidGoogle11.0 (including)11.0 (including)
AndroidGoogle12.0 (including)12.0 (including)
AndroidGoogle12.1 (including)12.1 (including)
Android-framework-23Ubuntubionic*
Android-framework-23Ubuntudevel*
Android-framework-23Ubuntuesm-apps/bionic*
Android-framework-23Ubuntuesm-apps/focal*
Android-framework-23Ubuntuesm-apps/jammy*
Android-framework-23Ubuntuesm-apps/noble*
Android-framework-23Ubuntufocal*
Android-framework-23Ubuntujammy*
Android-framework-23Ubuntukinetic*
Android-framework-23Ubuntulunar*
Android-framework-23Ubuntumantic*
Android-framework-23Ubuntunoble*
Android-framework-23Ubuntuoracular*
Android-framework-23Ubuntutrusty*
Android-framework-23Ubuntuxenial*

References