Description
The Zygote process in Android 4.0.3 and earlier accepts fork requests from processes with arbitrary UIDs, which allows remote attackers to cause a denial of service (reboot loop) via a crafted application.
Exploits (1)
References (2)
Core 2
Core References
Various Sources x_refsource_misc
http://www.ai-lab.it/merlo/publications/DoSAndroid.pdf
Issue Tracking x_refsource_confirm
https://code.google.com/p/android-source-browsing/source/detail?repo=platform--system--core&r=e7fd911fd42b
Scores
EPSS
0.1007
EPSS Percentile
93.1%
Details
CWE
CWE-399
Status
published
Products (30)
google/android
1.0
google/android
1.1
google/android
1.5
google/android
1.6
google/android
2.0
google/android
2.0.1
google/android
2.1
google/android
2.2 (2 CPE variants)
google/android
2.2.1
google/android
2.2.2
... and 20 more
Published
Oct 07, 2012
Tracked Since
Feb 18, 2026