{"id":"ASB-A-147358092","details":"In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improper input validation. This could lead to remote denial of service if a malicious contact file is received, with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-147358092","CVE-2020-0442"],"modified":"2026-06-12T15:08:17.296522730Z","published":"2020-11-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2020-11-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/frameworks/base/+/aaf6b40e1746db6189f6078dcd28d8f153a4cc50"}],"affected":[{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11-next:0"},{"fixed":"11-next:2020-11-01"}]}],"versions":["11-next"],"ecosystem_specific":{"severity":"Critical","fixes":["https://android.googlesource.com/platform/frameworks/base/+/c953fdf6bc498ca791aed49df04e5a07c935b63a"],"spl":"2020-11-01","types":["DoS"],"vanir_signatures":[{"signature_type":"Line","id":"ASB-A-147358092-397edf27","digest":{"threshold":0.9,"line_hashes":["25693081011143403965924570554327340062","145135667773462807188212350943050247915","103801210461441284299338172224434577144","268695753093872796919241450464110276483","46261083463634891044944826171838452135","176910514098118386474826865368856580128","98526589191053999908616954323828412117","128177431757207050536224790976428229825","319607130368601865965098141551601944972","107251892173742551941786143315072969027","275639386799706093579977400228926095134","310687014227499283566324898602218088852"]},"target":{"file":"core/java/android/app/Notification.java"},"deprecated":false,"source":"https://android.googlesource.com/platform/frameworks/base/+/c953fdf6bc498ca791aed49df04e5a07c935b63a","signature_version":"v1"},{"signature_type":"Function","source":"https://android.googlesource.com/platform/frameworks/base/+/c953fdf6bc498ca791aed49df04e5a07c935b63a","signature_version":"v1","target":{"file":"core/java/android/app/Notification.java","function":"Message"},"deprecated":false,"digest":{"length":176,"function_hash":"884783211642599066431883859307243095"},"id":"ASB-A-147358092-761f8b42"},{"signature_type":"Function","source":"https://android.googlesource.com/platform/frameworks/base/+/c953fdf6bc498ca791aed49df04e5a07c935b63a","digest":{"length":644,"function_hash":"222671025270688948635880737328659672300"},"target":{"file":"core/java/android/app/Notification.java","function":"toBundle"},"deprecated":false,"signature_version":"v1","id":"ASB-A-147358092-7a94299d"}]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-147358092.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0:0"},{"fixed":"8.0:2020-11-01"}]}],"versions":["8.0"],"ecosystem_specific":{"severity":"Critical","fixes":["https://android.googlesource.com/platform/frameworks/base/+/db023fcd738bb054402b771e5de5d758db526e30"],"spl":"2020-11-01","types":["DoS"],"vanir_signatures":[{"signature_type":"Function","source":"https://android.googlesource.com/platform/frameworks/base/+/db023fcd738bb054402b771e5de5d758db526e30","digest":{"length":481,"function_hash":"249850538892017593367435450928172592955"},"target":{"file":"core/java/android/app/Notification.java","function":"toBundle"},"deprecated":false,"signature_version":"v1","id":"ASB-A-147358092-c2d4c3ea"},{"signature_type":"Function","source":"https://android.googlesource.com/platform/frameworks/base/+/db023fcd738bb054402b771e5de5d758db526e30","signature_version":"v1","target":{"file":"core/java/android/app/Notification.java","function":"Message"},"deprecated":false,"digest":{"length":111,"function_hash":"130325885489704397750759730523257976396"},"id":"ASB-A-147358092-c5c39679"},{"signature_type":"Line","source":"https://android.googlesource.com/platform/frameworks/base/+/db023fcd738bb054402b771e5de5d758db526e30","signature_version":"v1","target":{"file":"core/java/android/app/Notification.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["25693081011143403965924570554327340062","145135667773462807188212350943050247915","78086377271289137333884542052049714539","56200141793655099869644449185924752249","313030175786482230069013616059698900122","27246985446692965280412607529203410146","223230047906985161320695007039713239736","82166126420729959545926416641025738484","104985517583945412739508227244376745054","54005927267847672694205859340955290389","223193595611124957030305446690472011801","303687947021586481106450517505084892623"]},"id":"ASB-A-147358092-f7e2d9e4"}]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-147358092.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.1:0"},{"fixed":"8.1:2020-11-01"}]}],"versions":["8.1"],"ecosystem_specific":{"severity":"Critical","fixes":["https://android.googlesource.com/platform/frameworks/base/+/f6f287a1efc76ef90e8caea952fffee862359015"],"spl":"2020-11-01","types":["DoS"],"vanir_signatures":[{"signature_type":"Function","id":"ASB-A-147358092-b892d1fe","digest":{"length":111,"function_hash":"130325885489704397750759730523257976396"},"target":{"file":"core/java/android/app/Notification.java","function":"Message"},"deprecated":false,"source":"https://android.googlesource.com/platform/frameworks/base/+/f6f287a1efc76ef90e8caea952fffee862359015","signature_version":"v1"},{"signature_type":"Line","source":"https://android.googlesource.com/platform/frameworks/base/+/f6f287a1efc76ef90e8caea952fffee862359015","signature_version":"v1","target":{"file":"core/java/android/app/Notification.java"},"deprecated":false,"id":"ASB-A-147358092-ccf5e19c","digest":{"threshold":0.9,"line_hashes":["25693081011143403965924570554327340062","145135667773462807188212350943050247915","78086377271289137333884542052049714539","56200141793655099869644449185924752249","313030175786482230069013616059698900122","27246985446692965280412607529203410146","223230047906985161320695007039713239736","82166126420729959545926416641025738484","104985517583945412739508227244376745054","54005927267847672694205859340955290389","223193595611124957030305446690472011801","303687947021586481106450517505084892623"]}},{"signature_type":"Function","source":"https://android.googlesource.com/platform/frameworks/base/+/f6f287a1efc76ef90e8caea952fffee862359015","signature_version":"v1","target":{"file":"core/java/android/app/Notification.java","function":"toBundle"},"deprecated":false,"id":"ASB-A-147358092-f48bf02f","digest":{"length":481,"function_hash":"249850538892017593367435450928172592955"}}]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-147358092.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9:0"},{"fixed":"9:2020-11-01"}]}],"versions":["9"],"ecosystem_specific":{"severity":"Critical","types":["DoS"],"spl":"2020-11-01","fixes":["https://android.googlesource.com/platform/frameworks/base/+/7857da643150e9b29f729632c68e705d7ba1ad48"],"vanir_signatures":[{"signature_type":"Function","id":"ASB-A-147358092-35738ed9","digest":{"length":644,"function_hash":"222671025270688948635880737328659672300"},"target":{"file":"core/java/android/app/Notification.java","function":"toBundle"},"deprecated":false,"source":"https://android.googlesource.com/platform/frameworks/base/+/7857da643150e9b29f729632c68e705d7ba1ad48","signature_version":"v1"},{"signature_type":"Function","id":"ASB-A-147358092-5774d460","digest":{"length":176,"function_hash":"884783211642599066431883859307243095"},"target":{"file":"core/java/android/app/Notification.java","function":"Message"},"deprecated":false,"source":"https://android.googlesource.com/platform/frameworks/base/+/7857da643150e9b29f729632c68e705d7ba1ad48","signature_version":"v1"},{"signature_type":"Line","source":"https://android.googlesource.com/platform/frameworks/base/+/7857da643150e9b29f729632c68e705d7ba1ad48","signature_version":"v1","target":{"file":"core/java/android/app/Notification.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["25693081011143403965924570554327340062","145135667773462807188212350943050247915","123844992865351715585790036542023721288","270179343523045032144507667929111654064","46261083463634891044944826171838452135","176910514098118386474826865368856580128","98526589191053999908616954323828412117","128177431757207050536224790976428229825","319607130368601865965098141551601944972","107251892173742551941786143315072969027","275639386799706093579977400228926095134","310687014227499283566324898602218088852"]},"id":"ASB-A-147358092-b4d29889"}]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-147358092.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10:0"},{"fixed":"10:2020-11-01"}]}],"versions":["10"],"ecosystem_specific":{"severity":"Critical","fixes":["https://android.googlesource.com/platform/frameworks/base/+/978d31e45a67dba9d57d45a26c1d521300ba1b6f"],"spl":"2020-11-01","types":["DoS"],"vanir_signatures":[{"signature_type":"Function","id":"ASB-A-147358092-7e5960e5","digest":{"length":644,"function_hash":"222671025270688948635880737328659672300"},"target":{"file":"core/java/android/app/Notification.java","function":"toBundle"},"deprecated":false,"source":"https://android.googlesource.com/platform/frameworks/base/+/978d31e45a67dba9d57d45a26c1d521300ba1b6f","signature_version":"v1"},{"signature_type":"Function","source":"https://android.googlesource.com/platform/frameworks/base/+/978d31e45a67dba9d57d45a26c1d521300ba1b6f","digest":{"length":176,"function_hash":"884783211642599066431883859307243095"},"target":{"file":"core/java/android/app/Notification.java","function":"Message"},"deprecated":false,"signature_version":"v1","id":"ASB-A-147358092-c6d6ecb4"},{"signature_type":"Line","source":"https://android.googlesource.com/platform/frameworks/base/+/978d31e45a67dba9d57d45a26c1d521300ba1b6f","signature_version":"v1","target":{"file":"core/java/android/app/Notification.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["25693081011143403965924570554327340062","145135667773462807188212350943050247915","103801210461441284299338172224434577144","268695753093872796919241450464110276483","46261083463634891044944826171838452135","176910514098118386474826865368856580128","98526589191053999908616954323828412117","128177431757207050536224790976428229825","319607130368601865965098141551601944972","107251892173742551941786143315072969027","275639386799706093579977400228926095134","310687014227499283566324898602218088852"]},"id":"ASB-A-147358092-f2a524d2"}]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-147358092.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11:0"},{"fixed":"11:2020-11-01"}]}],"versions":["11"],"ecosystem_specific":{"severity":"Critical","types":["DoS"],"spl":"2020-11-01","fixes":["https://android.googlesource.com/platform/frameworks/base/+/a19f9ed2b1c04fe7e73bab1a8ca51400dbf8a07a"],"vanir_signatures":[{"signature_type":"Function","id":"ASB-A-147358092-647226a5","signature_version":"v1","target":{"file":"core/java/android/app/Notification.java","function":"Message"},"deprecated":false,"digest":{"length":176,"function_hash":"884783211642599066431883859307243095"},"source":"https://android.googlesource.com/platform/frameworks/base/+/a19f9ed2b1c04fe7e73bab1a8ca51400dbf8a07a"},{"signature_type":"Line","source":"https://android.googlesource.com/platform/frameworks/base/+/a19f9ed2b1c04fe7e73bab1a8ca51400dbf8a07a","signature_version":"v1","target":{"file":"core/java/android/app/Notification.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["25693081011143403965924570554327340062","145135667773462807188212350943050247915","103801210461441284299338172224434577144","268695753093872796919241450464110276483","46261083463634891044944826171838452135","176910514098118386474826865368856580128","98526589191053999908616954323828412117","128177431757207050536224790976428229825","319607130368601865965098141551601944972","107251892173742551941786143315072969027","275639386799706093579977400228926095134","310687014227499283566324898602218088852"]},"id":"ASB-A-147358092-6c7fbe17"},{"signature_type":"Function","id":"ASB-A-147358092-6f727d4d","digest":{"length":644,"function_hash":"222671025270688948635880737328659672300"},"target":{"file":"core/java/android/app/Notification.java","function":"toBundle"},"deprecated":false,"source":"https://android.googlesource.com/platform/frameworks/base/+/a19f9ed2b1c04fe7e73bab1a8ca51400dbf8a07a","signature_version":"v1"}]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-147358092.json"}}],"schema_version":"1.7.5"}