Description
In parsePartHeaders of multiple files, there is a possible persistent denial of service due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the parsePartHeaders function across multiple files in the Android operating system. The function performs insufficient input validation, allowing an attacker to supply crafted input that can cause the system to enter a persistent denial‑of‑service state. The attack does not require any elevated execution privileges and can be carried out remotely without any user interaction. If successfully exploited, an attacker can render the device unusable by causing the relevant processes to hang or consume excessive resources.

Affected Systems

All devices running the Android operating system are potentially affected, as the flaw exists in core system components that are deployed across many Android releases. The specific affected versions are not listed in the CVE data, but the issue is addressed in the 2026‑09‑01 security bulletin, implying earlier versions prior to that update may be vulnerable.

Risk and Exploitability

The EPSS score is < 1% (approximately 0.00158), indicating a very low but non-zero likelihood of exploitation. The CVSS score of 6.5 categorizes this flaw as medium severity. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be remote, involving the delivery of malicious files or attachments that trigger the parsePartHeaders routine. Because the flaw causes a persistent service disruption rather than code execution, the primary risk is availability loss for the device.

Generated by OpenCVE AI on September 11, 2026 at 00:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the 2026‑09‑01 security update to Android, which addresses the parsePartHeaders denial‑of‑service flaw.
  • Avoid opening or processing untrusted files from unknown sources, especially those received via email or messaging apps, until the device is patched.
  • Monitor the device for abnormal crashes or prolonged resource consumption and report them to your device manufacturer or support team.

Generated by OpenCVE AI on September 11, 2026 at 00:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Fri, 11 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title Android parsePartHeaders Denial of Service in Core System

Thu, 10 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Persistent Denial of Service via Improper Input Validation in Android parsePartHeaders
Weaknesses CWE-400

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Persistent Denial of Service via Improper Input Validation in Android parsePartHeaders
Weaknesses CWE-400

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In parsePartHeaders of multiple files, there is a possible persistent denial of service due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-10T15:40:17.859Z

Reserved: 2026-06-16T17:37:58.179Z

Link: CVE-2026-55256

cve-icon Vulnrichment

Updated: 2026-09-10T15:40:08.632Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:18:00.540

Modified: 2026-09-24T15:42:54.473

Link: CVE-2026-55256

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T22:00:04Z

Weaknesses
  • CWE-20

    Improper Input Validation