Sceawere

Vulnerability Detail

CVE-2026-58865UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

PduParser Persistent Denial of Service

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
2h ago
Vendor
Google
Product
Android
Attack Type
Denial of service
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-05T19:17:25.183Z",
  "pubdate": "2026-10-05T19:17:25.183Z",
  "executiveSummary": "A critical security vulnerability has been identified within the PduParser.java component, involving a missing bounds check that facilitates a persistent denial of service (DoS) condition.\nThe vulnerability allows a remote, unauthenticated attacker to induce a state of service unavailability without requiring user interaction or elevated system privileges.\nBy manipulating malicious PDU (Protocol Data Unit) inputs, an attacker can trigger uncontrolled resource consumption or application crashes within the parser, effectively rendering the affected functionality unresponsive.\nThe absence of validation logic during the parsing process exposes the system to remote exploitation, posing a significant risk to the availability and stability of the target application.\nThis vulnerability is particularly dangerous as it does not require prior knowledge of the target environment or authentication, making the attack surface broad for any system processing untrusted PDU data via the vulnerable PduParser.java implementation.",
  "technicalDetails": "The root cause of this vulnerability is an improper input validation flaw residing within multiple functions of PduParser.java. Specifically, the implementation fails to perform rigorous bounds checking on incoming data structures during the parsing of PDU packets.\nIn a secure implementation, a parser must validate the length and integrity of data fields against predefined buffer or structure constraints before attempting memory allocation or data processing operations. PduParser.java lacks these boundary conditions, allowing maliciously crafted inputs to bypass length validation checks.\nThe attack flow initiates when an attacker sends a specially crafted PDU packet to a target system or application that utilizes PduParser.java for data processing. Upon receipt, the vulnerable component attempts to process the payload without verifying if the data size exceeds expected limits or overlaps with restricted memory segments.\nBecause the parser relies on these unvalidated inputs to navigate data offsets or iterate through loops, the malformed input triggers an exception or an out-of-bounds access. This leads to a catastrophic failure of the service, resulting in a persistent denial of service state. Since the error occurs at the parsing layer, the service may remain non-functional until a manual restart or systemic recovery intervention is performed, as the state of the parser becomes corrupted or deadlocked.\nThe exploitation does not require the attacker to possess elevated privileges or interact with a local user session, as the processing of PDUs is typically performed by high-level network-facing services. The vulnerability is triggered automatically as soon as the parser attempts to ingest the malicious payload, placing the entire system at risk of remote exploitation over the underlying network protocol.\nPost-exploitation, the impact is strictly centered on service availability. While the flaw specifically enables a DoS, it highlights a failure in defensive programming practices related to buffer management and input sanitation within the component. The inability to handle anomalous input values gracefully demonstrates a lack of robust error handling, which could potentially be leveraged in more complex exploit chains aimed at destabilizing critical background processes."
}
CVE-2026-58865: PduParser Persistent Denial of Service (HIGH Severity, CVSS: 7.5) | Sceawere