Description
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-06-01
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an integer overflow in multiple functions within the file ubsan_throwing_runtime.cpp that can cause a persistent denial of service. It requires no additional privileges and does not need user interaction, so an attacker could trigger it from a remote source by supplying crafted input that overflows internal counters or memory sizes, potentially crashing the process or causing the device to become unresponsive and impacting availability. Based on the description, it is inferred that the attack vector is remote network-based.

Affected Systems

The affected vendor is Google Android. The specific Android releases that contain the vulnerable code are not listed in the data provided, so administrators must verify whether their devices run versions that include this code; a vendor security bulletin should list the affected builds once a patch is released. It is inferred that any build incorporating the vulnerable ubsan_throwing_runtime.cpp code could be affected.

Risk and Exploitability

The CVSS score is 6.5, and the EPSS score is not provided, but the description indicates that exploitation can occur remotely without user interaction, which typically signals a high likelihood of successful attacks once an attacker has network access to the device. Given the lack of EPSS data, it is inferred that the precise likelihood of exploitation is uncertain, although the remote nature suggests a non‑negligible risk. The vulnerability is not listed in CISA’s KEV catalog, meaning no publicly known widespread exploitation has been reported. The primary risk is to availability, allowing attackers to disrupt device operation.

Generated by OpenCVE AI on June 2, 2026 at 02:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android security update that includes a fix for the ubsan_throwing_runtime.cpp integer overflow.
  • If a patch is not yet released, restrict network exposure of services that may trigger the vulnerable functions by configuring firewall rules or applying host‑based access controls.
  • Run regular vulnerability scans to detect devices that may still be running affected Android versions, and remediate them through over‑the‑air updates or manual ROM upgrades.

Generated by OpenCVE AI on June 2, 2026 at 02:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 02 Jun 2026 02:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Android ubsan_throwing_runtime.cpp Could Lead to Persistent Denial of Service

Tue, 02 Jun 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 01 Jun 2026 22:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Android ubsan_throwing_runtime.cpp Could Lead to Persistent Denial of Service
First Time appeared Google
Google android
Weaknesses CWE-190
Vendors & Products Google
Google android

Mon, 01 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Description In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-06-01T23:41:55.152Z

Reserved: 2025-10-15T15:39:26.832Z

Link: CVE-2026-0039

cve-icon Vulnrichment

Updated: 2026-06-01T23:41:37.401Z

cve-icon NVD

Status : Received

Published: 2026-06-01T22:16:19.610

Modified: 2026-06-02T00:16:33.580

Link: CVE-2026-0039

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T02:30:16Z

Weaknesses