CVE-2026-0039: Integer Overflow
Published Jun 1, 2026
·Updated
In multiple functions of ubsanthrowingruntime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
7 affected components
llvm compiler-rt
Google Android=14.0
Google Android=15.0
Google Android=16.0
Google Android=16.0-qpr2_beta_1
Google Android=16.0-qpr2_beta_2
Google Android=16.0-qpr2_beta_3
Event History
Jun 1, 2026
CVE Published
via MITRE·09:14 PM
Data Sourced
via MITRE·09:14 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-0039?
The severity of CVE-2026-0039 is medium with a score of 6.5.
2
How do I fix CVE-2026-0039?
To mitigate CVE-2026-0039, update to the latest version of Google Android and llvm compiler-rt that addresses this vulnerability.
3
What impact does CVE-2026-0039 have on systems?
CVE-2026-0039 can lead to a persistent denial of service, allowing remote attacks without the need for user interaction.
4
Which systems are affected by CVE-2026-0039?
CVE-2026-0039 affects Google Android and the llvm compiler-rt.
5
Is user interaction required to exploit CVE-2026-0039?
No, user interaction is not required for the exploitation of CVE-2026-0039.