CVE-2026-58865
In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.22%
- Percentile among all scored CVEs: 12
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1190Exploit Public-Facing Applicationinitial access85 % - Primary impact
T1499.004Application or System Exploitationimpact80 %
AV:N/PR:N/UI:N indica explotación remota sin privilegios (T1190). CWE-119 (desbordamiento de búfer) sin verificación de límites en PduParser causa DoS persistente remoto (T1499.004).
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
CWEs
- CWE-119
References
Raw JSON (NVD)
Show
{
"id": "CVE-2026-58865",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-58865",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-10-05T18:58:16.740162Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@android.com",
"affectedData": [
{
"vendor": "Google",
"product": "Android",
"versions": [
{
"status": "affected",
"version": "17"
},
{
"status": "affected",
"version": "16-qpr2"
},
{
"status": "affected",
"version": "16"
},
{
"status": "affected",
"version": "15"
},
{
"status": "affected",
"version": "14"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-10-05T19:17:25.183",
"references": [
{
"url": "https://source.android.com/docs/security/bulletin/2026/2026-10-01",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "security@android.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation."
}
],
"lastModified": "2026-10-07T15:14:22.670",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2700BCC5-634D-4EC6-AB67-5B678D5F951D"
},
{
"criteria": "cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8538774C-906D-4B03-A3E7-FA7A55E0DA9E"
},
{
"criteria": "cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "02882AB1-7993-47DD-84A0-8DF4272D85ED"
},
{
"criteria": "cpe:2.3:o:google:android:16.0:qpr2_beta_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FD695F32-4A73-4846-B1A1-04FF266E9C15"
},
{
"criteria": "cpe:2.3:o:google:android:16.0:qpr2_beta_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3DE9F018-8704-476B-8D59-F63F8486E231"
},
{
"criteria": "cpe:2.3:o:google:android:16.0:qpr2_beta_3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE95A642-4330-4F65-B028-3BA597D30F32"
},
{
"criteria": "cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E3D15FD9-304E-4270-81C7-C8D9024D457D"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@android.com"
}