Android DNG SDK Huffman Decoding Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the Android DNG SDK, specifically within the Huffman decoding process of the DNG lossless JPEG component. The issue arises from the use of uninitialized data, which can lead to a crash. This vulnerability can be exploited remotely without requiring any additional execution privileges or user interaction.

Impact

Exploitation of this vulnerability causes a crash, leading to a denial-of-service condition on the affected device.

Remediation

Users can update their devices to the March 2025 security patch level to address this vulnerability.

Added: Aug 26, 2025, 11:33 PM
Updated: Aug 26, 2025, 11:33 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.1
remediation
0.0
relevance
0.4
threat
3.2
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.