In createNotificationChannel of NotificationManager.java, there is a possible way to make the device unusable and require factory reset due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-240422263
CVE-2022-20482 - Medium Severity Vulnerability
Vulnerable Library - baseandroid-10.0.0_r34
Android framework classes and services
Library home page: https://android.googlesource.com/platform/frameworks/base
Found in HEAD commit: ad904931c8573db6b23cb187b24bf22317d51554
Found in base branch: master
Vulnerable Source Files (1)
/services/core/java/com/android/server/notification/PreferencesHelper.java
Vulnerability Details
In createNotificationChannel of NotificationManager.java, there is a possible way to make the device unusable and require factory reset due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-240422263
Publish Date: 2022-12-13
URL: CVE-2022-20482
CVSS 3 Score Details (5.5)
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Local - Attack Complexity: Low - Privileges Required: Low - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: None - Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://android.googlesource.com/platform/frameworks/base/+/f528b337dd48b7e8071269e07e610bd4a3668c75
Release Date: 2022-12-13
Fix Resolution: android-13.0.0_r16
Step up your Open Source Security Game with Mend here