CVE-2025-36917

MEDIUM

Google Android - Buffer Overflow

Title source: rule
STIX 2.1

Description

In SwDcpItg of up_L2commonPdcpSecurity.cpp, there is a possible denial of service due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0019
EPSS Percentile 41.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-120
Status published
Products (1)
google/android
Published Dec 11, 2025
Tracked Since Feb 18, 2026