{"id":"ASB-A-347735428","details":"In dng_lossless_decoder::HuffDecode of dng_lossless_jpeg.cpp, there is a possible way to cause a crash due to uninitialized data. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-347735428","CVE-2025-0081"],"modified":"2026-04-14T15:05:17.852631Z","published":"2025-03-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2025-03-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/external/dng_sdk/+/7fc02c8d5af37c97b325dc2956f4a6117c145c2f"}],"affected":[{"package":{"name":"platform/external/dng_sdk","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"15-next:0"},{"fixed":"15-next:2025-03-01"}]}],"versions":["15-next"],"ecosystem_specific":{"types":["DoS"],"severity":"Critical","vanir_signatures":[{"signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/external/dng_sdk/+/a22d1f0f07d998a53dd49a941d3a588f55b36399","target":{"function":"dng_lossless_decoder::HuffDecode","file":"source/dng_lossless_jpeg.cpp"},"signature_type":"Function","id":"ASB-A-347735428-07f2a8c3","digest":{"length":481,"function_hash":"44118990782442989971520362830657759096"}},{"signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/external/dng_sdk/+/a22d1f0f07d998a53dd49a941d3a588f55b36399","target":{"file":"source/dng_lossless_jpeg.cpp"},"signature_type":"Line","id":"ASB-A-347735428-75f7b436","digest":{"threshold":0.9,"line_hashes":["202547611177054701034872398982999876811","159620168567637667498119843984396843211","44069793425545066664780021469054570000"]}}],"spl":"2025-03-01","fixes":["https://android.googlesource.com/platform/external/dng_sdk/+/a22d1f0f07d998a53dd49a941d3a588f55b36399"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-347735428.json"}},{"package":{"name":"platform/external/dng_sdk","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12:0"},{"fixed":"12:2025-03-01"}]}],"versions":["12"],"ecosystem_specific":{"types":["DoS"],"severity":"Critical","vanir_signatures":[{"signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/external/dng_sdk/+/ef6549c8eb3b202e8b47c41ba39d7957274aa12b","target":{"function":"dng_lossless_decoder::HuffDecode","file":"source/dng_lossless_jpeg.cpp"},"signature_type":"Function","id":"ASB-A-347735428-6f7c4138","digest":{"length":481,"function_hash":"44118990782442989971520362830657759096"}},{"signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/external/dng_sdk/+/ef6549c8eb3b202e8b47c41ba39d7957274aa12b","target":{"file":"source/dng_lossless_jpeg.cpp"},"signature_type":"Line","id":"ASB-A-347735428-b6d59679","digest":{"threshold":0.9,"line_hashes":["202547611177054701034872398982999876811","159620168567637667498119843984396843211","44069793425545066664780021469054570000"]}}],"spl":"2025-03-01","fixes":["https://android.googlesource.com/platform/external/dng_sdk/+/ef6549c8eb3b202e8b47c41ba39d7957274aa12b"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-347735428.json"}},{"package":{"name":"platform/external/dng_sdk","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12L:0"},{"fixed":"12L:2025-03-01"}]}],"versions":["12L"],"ecosystem_specific":{"types":["DoS"],"severity":"Critical","vanir_signatures":[{"signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/external/dng_sdk/+/97cbb86f575c92ccd097407bb1fe5ad9bb532944","target":{"file":"source/dng_lossless_jpeg.cpp"},"signature_type":"Line","id":"ASB-A-347735428-88cce0b2","digest":{"threshold":0.9,"line_hashes":["202547611177054701034872398982999876811","159620168567637667498119843984396843211","44069793425545066664780021469054570000"]}},{"signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/external/dng_sdk/+/97cbb86f575c92ccd097407bb1fe5ad9bb532944","target":{"function":"dng_lossless_decoder::HuffDecode","file":"source/dng_lossless_jpeg.cpp"},"signature_type":"Function","id":"ASB-A-347735428-ace64fae","digest":{"length":481,"function_hash":"44118990782442989971520362830657759096"}}],"spl":"2025-03-01","fixes":["https://android.googlesource.com/platform/external/dng_sdk/+/97cbb86f575c92ccd097407bb1fe5ad9bb532944"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-347735428.json"}},{"package":{"name":"platform/external/dng_sdk","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"15:0"},{"fixed":"15:2025-03-01"}]}],"versions":["15"],"ecosystem_specific":{"types":["DoS"],"severity":"Critical","vanir_signatures":[{"signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/external/dng_sdk/+/6fd49d6ecdf53aa96b290ee5b3e30a7d73c71679","target":{"function":"dng_lossless_decoder::HuffDecode","file":"source/dng_lossless_jpeg.cpp"},"signature_type":"Function","id":"ASB-A-347735428-6111fb64","digest":{"length":481,"function_hash":"44118990782442989971520362830657759096"}},{"signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/external/dng_sdk/+/6fd49d6ecdf53aa96b290ee5b3e30a7d73c71679","target":{"file":"source/dng_lossless_jpeg.cpp"},"signature_type":"Line","id":"ASB-A-347735428-df2e0ae7","digest":{"threshold":0.9,"line_hashes":["202547611177054701034872398982999876811","159620168567637667498119843984396843211","44069793425545066664780021469054570000"]}}],"spl":"2025-03-01","fixes":["https://android.googlesource.com/platform/external/dng_sdk/+/6fd49d6ecdf53aa96b290ee5b3e30a7d73c71679"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-347735428.json"}},{"package":{"name":"platform/external/dng_sdk","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13:0"},{"fixed":"13:2025-03-01"}]}],"versions":["13"],"ecosystem_specific":{"types":["DoS"],"severity":"Critical","vanir_signatures":[{"signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/external/dng_sdk/+/d125388473163ed70452c6e615b3c788805e0168","target":{"file":"source/dng_lossless_jpeg.cpp"},"signature_type":"Line","id":"ASB-A-347735428-36c60252","digest":{"threshold":0.9,"line_hashes":["202547611177054701034872398982999876811","159620168567637667498119843984396843211","44069793425545066664780021469054570000"]}},{"signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/external/dng_sdk/+/d125388473163ed70452c6e615b3c788805e0168","target":{"function":"dng_lossless_decoder::HuffDecode","file":"source/dng_lossless_jpeg.cpp"},"signature_type":"Function","id":"ASB-A-347735428-921f5dfc","digest":{"length":481,"function_hash":"44118990782442989971520362830657759096"}}],"spl":"2025-03-01","fixes":["https://android.googlesource.com/platform/external/dng_sdk/+/d125388473163ed70452c6e615b3c788805e0168"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-347735428.json"}},{"package":{"name":"platform/external/dng_sdk","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14:0"},{"fixed":"14:2025-03-01"}]}],"versions":["14"],"ecosystem_specific":{"types":["DoS"],"severity":"Critical","vanir_signatures":[{"signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/external/dng_sdk/+/89f7028f91aa2979fa88f51cdd37b6444b5cd9d9","target":{"file":"source/dng_lossless_jpeg.cpp"},"signature_type":"Line","id":"ASB-A-347735428-774e0d05","digest":{"threshold":0.9,"line_hashes":["202547611177054701034872398982999876811","159620168567637667498119843984396843211","44069793425545066664780021469054570000"]}},{"signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/external/dng_sdk/+/89f7028f91aa2979fa88f51cdd37b6444b5cd9d9","target":{"function":"dng_lossless_decoder::HuffDecode","file":"source/dng_lossless_jpeg.cpp"},"signature_type":"Function","id":"ASB-A-347735428-b647a1b8","digest":{"length":481,"function_hash":"44118990782442989971520362830657759096"}}],"spl":"2025-03-01","fixes":["https://android.googlesource.com/platform/external/dng_sdk/+/89f7028f91aa2979fa88f51cdd37b6444b5cd9d9"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-347735428.json"}}],"schema_version":"1.7.5"}