CVE Vulnerabilities

CVE-2023-40074

Published: Dec 04, 2023 | Modified: Feb 02, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

In saveToXml of PersistableBundle.java, invalid data could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected Software

Name Vendor Start Version End Version
Android Google 11.0 (including) 11.0 (including)
Android Google 12.0 (including) 12.0 (including)
Android Google 12.1 (including) 12.1 (including)
Android Google 13.0 (including) 13.0 (including)
Android-framework-23 Ubuntu bionic *
Android-framework-23 Ubuntu devel *
Android-framework-23 Ubuntu esm-apps/bionic *
Android-framework-23 Ubuntu esm-apps/focal *
Android-framework-23 Ubuntu esm-apps/jammy *
Android-framework-23 Ubuntu esm-apps/noble *
Android-framework-23 Ubuntu focal *
Android-framework-23 Ubuntu jammy *
Android-framework-23 Ubuntu lunar *
Android-framework-23 Ubuntu mantic *
Android-framework-23 Ubuntu noble *
Android-framework-23 Ubuntu oracular *
Android-framework-23 Ubuntu trusty *
Android-framework-23 Ubuntu xenial *
Android-platform-frameworks-base Ubuntu bionic *
Android-platform-frameworks-base Ubuntu devel *
Android-platform-frameworks-base Ubuntu esm-apps/bionic *
Android-platform-frameworks-base Ubuntu esm-apps/focal *
Android-platform-frameworks-base Ubuntu esm-apps/jammy *
Android-platform-frameworks-base Ubuntu esm-apps/noble *
Android-platform-frameworks-base Ubuntu esm-apps/xenial *
Android-platform-frameworks-base Ubuntu focal *
Android-platform-frameworks-base Ubuntu jammy *
Android-platform-frameworks-base Ubuntu lunar *
Android-platform-frameworks-base Ubuntu mantic *
Android-platform-frameworks-base Ubuntu noble *
Android-platform-frameworks-base Ubuntu oracular *
Android-platform-frameworks-base Ubuntu trusty *
Android-platform-frameworks-base Ubuntu xenial *

References