Sceawere
Vulnerability Detail
CVE-2026-58865UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
PduParser Persistent Denial of Service
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 2h ago
- Vendor
- Product
- Android
- Attack Type
- Denial of service
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-05T19:17:25.183Z",
"pubdate": "2026-10-05T19:17:25.183Z",
"executiveSummary": "A critical security vulnerability has been identified within the PduParser.java component, involving a missing bounds check that facilitates a persistent denial of service (DoS) condition.\nThe vulnerability allows a remote, unauthenticated attacker to induce a state of service unavailability without requiring user interaction or elevated system privileges.\nBy manipulating malicious PDU (Protocol Data Unit) inputs, an attacker can trigger uncontrolled resource consumption or application crashes within the parser, effectively rendering the affected functionality unresponsive.\nThe absence of validation logic during the parsing process exposes the system to remote exploitation, posing a significant risk to the availability and stability of the target application.\nThis vulnerability is particularly dangerous as it does not require prior knowledge of the target environment or authentication, making the attack surface broad for any system processing untrusted PDU data via the vulnerable PduParser.java implementation.",
"technicalDetails": "The root cause of this vulnerability is an improper input validation flaw residing within multiple functions of PduParser.java. Specifically, the implementation fails to perform rigorous bounds checking on incoming data structures during the parsing of PDU packets.\nIn a secure implementation, a parser must validate the length and integrity of data fields against predefined buffer or structure constraints before attempting memory allocation or data processing operations. PduParser.java lacks these boundary conditions, allowing maliciously crafted inputs to bypass length validation checks.\nThe attack flow initiates when an attacker sends a specially crafted PDU packet to a target system or application that utilizes PduParser.java for data processing. Upon receipt, the vulnerable component attempts to process the payload without verifying if the data size exceeds expected limits or overlaps with restricted memory segments.\nBecause the parser relies on these unvalidated inputs to navigate data offsets or iterate through loops, the malformed input triggers an exception or an out-of-bounds access. This leads to a catastrophic failure of the service, resulting in a persistent denial of service state. Since the error occurs at the parsing layer, the service may remain non-functional until a manual restart or systemic recovery intervention is performed, as the state of the parser becomes corrupted or deadlocked.\nThe exploitation does not require the attacker to possess elevated privileges or interact with a local user session, as the processing of PDUs is typically performed by high-level network-facing services. The vulnerability is triggered automatically as soon as the parser attempts to ingest the malicious payload, placing the entire system at risk of remote exploitation over the underlying network protocol.\nPost-exploitation, the impact is strictly centered on service availability. While the flaw specifically enables a DoS, it highlights a failure in defensive programming practices related to buffer management and input sanitation within the component. The inability to handle anomalous input values gracefully demonstrates a lack of robust error handling, which could potentially be leveraged in more complex exploit chains aimed at destabilizing critical background processes."
}