CVE-2026-0042: Medium severity llvm compiler-rt UBSan runtime vulnerability
Published Jun 1, 2026
·Updated
In multiple functions of ubsanthrowingruntime.cpp, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
7 affected components
llvm compiler-rt UBSan runtime
Google Android=14.0
Google Android=15.0
Google Android=16.0
Google Android=16.0-qpr2_beta_1
Google Android=16.0-qpr2_beta_2
Google Android=16.0-qpr2_beta_3
Event History
Jun 1, 2026
CVE Published
via MITRE·09:14 PM
Data Sourced
via MITRE·09:14 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-0042?
CVE-2026-0042 has a medium severity score of 5.5 on the CVSS scale.
2
What are the potential impacts of CVE-2026-0042?
CVE-2026-0042 may lead to a local denial of service due to resource exhaustion.
3
How can CVE-2026-0042 be exploited?
CVE-2026-0042 can be exploited without any user interaction and does not require additional execution privileges.
4
What software is affected by CVE-2026-0042?
CVE-2026-0042 affects Google Android and the LLVM compiler-rt UBSan runtime.
5
What is the nature of the vulnerability in CVE-2026-0042?
CVE-2026-0042 involves possible persistent denial of service in multiple functions of ubsan_throwing_runtime.cpp.