Description
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a permanent denial of service due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-06-01
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A logic error in multiple functions of ubsan_throwing_runtime.cpp allows a permanent denial of service. The flaw means that once triggered the affected component stops functioning, effectively rendering the system unusable until a reboot or patch. The impact is a local denial of service; no elevated privileges are required and no remote exploitation is implied by the available data. The weakness can be categorized as a logic bug that leads to service unavailability.

Affected Systems

Google Android devices running any of the following releases are affected: Android 14.0, Android 15.0, Android 16.0, and Android 16.0:qpr2. The flaw resides in the UBSan runtime component of the operating system. Devices with these specific OS versions that include the buggy UBSan code are susceptible to the denial of service.

Risk and Exploitability

The EPSS score indicates a very low exploitation probability (<1%), and the vulnerability is not listed in the CISA KEV catalog at this time. Because the defect requires local execution and does not require special privileges, the risk largely depends on the density of the user base and whether the device can be easily physically accessed. With a CVSS score of 5.5 the vulnerability is categorized as medium severity, yet the permanent nature of the denial of service underscores a significant impact. The likely attack vector is local, as user interaction is not needed; the flaw can be triggered by normal device operation or by an application that uses the affected UBSan functions.

Generated by OpenCVE AI on June 3, 2026 at 05:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the latest Android security bulletin for updates addressing the UBSan runtime logic error and install any available security patches.
  • If a patch is not yet available, disable UBSan checks if possible via system configuration or device properties, and reboot.
  • Monitor system logs for UBSan-related crashes, and limit use of applications that may invoke affected functions until an official fix is released.

Generated by OpenCVE AI on June 3, 2026 at 05:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Jun 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:* cpe:2.3:o:google:android:16.0:qpr2_beta_1:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2_beta_2:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2_beta_3:*:*:*:*:*:*

Wed, 03 Jun 2026 11:15:00 +0000

Type Values Removed Values Added
Title Permanent Denial of Service via UBSan Runtime Logic Error on Android
Weaknesses CWE-400

Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Title Permanent Denial of Service via UBSan Runtime Logic Error
Weaknesses CWE-398
CWE-400

Tue, 02 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*

Tue, 02 Jun 2026 03:45:00 +0000

Type Values Removed Values Added
Title Permanent Denial of Service via UBSan Runtime Logic Error
Weaknesses CWE-398
CWE-400

Tue, 02 Jun 2026 02:15:00 +0000

Type Values Removed Values Added
Title Permanent Denial of Service via UBSan Runtime Logic Error
Weaknesses CWE-399
CWE-749

Tue, 02 Jun 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 01 Jun 2026 23:00:00 +0000

Type Values Removed Values Added
Title Permanent Denial of Service via UBSan Runtime Logic Error
First Time appeared Google
Google android
Weaknesses CWE-399
CWE-749
Vendors & Products Google
Google android

Mon, 01 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Description In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a permanent denial of service due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-06-01T23:22:38.060Z

Reserved: 2025-10-15T15:40:49.196Z

Link: CVE-2026-0067

cve-icon Vulnrichment

Updated: 2026-06-01T23:22:27.674Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-01T22:16:21.267

Modified: 2026-06-03T13:46:47.137

Link: CVE-2026-0067

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-03T05:30:16Z

Weaknesses