Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-689p-ppgm-x7pf

Опубликовано: 17 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 10
CVSS3: 5.5

Описание

In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible memory exhaustion attack due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible memory exhaustion attack due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

EPSS

Процентиль: 2%
0.00125
Низкий

10 Critical

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.5
nvd
2 месяца назад

In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible memory exhaustion attack due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

EPSS

Процентиль: 2%
0.00125
Низкий

10 Critical

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-400