CVE-2026-0041: Integer Overflow
In multiple functions of ubsanthrowingruntime.cpp, there is a possible UBSan failure due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network exposure of any service that links or loads the UBSan throwing runtime (ubsan_throwing_runtime.cpp). Apply firewall rules, ACLs, WAF rules, or network segmentation to allow access only from trusted hosts and networks to reduce likelihood of remote denial-of-service exploitation.
- Operational
Enable monitoring and incident response for UBSan failures and process crashes. Alert on UBSan-related errors or unexpected process termination, collect crash dumps/logs for analysis, and configure process supervision to automatically restart affected services to reduce downtime.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0041?
The severity of CVE-2026-0041 is rated medium with a CVSS score of 6.5.
What is the risk associated with CVE-2026-0041?
CVE-2026-0041 has a risk rating of 38.
How can I mitigate CVE-2026-0041?
To mitigate CVE-2026-0041, ensure that the latest security patches for Google Android and llvm compiler-rt are applied.
What impact does CVE-2026-0041 have?
CVE-2026-0041 can lead to a remote denial of service without requiring additional execution privileges.
Is user interaction required to exploit CVE-2026-0041?
No, user interaction is not needed to exploit CVE-2026-0041.