{"id":"ASB-A-425360742","details":"In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-425360742","CVE-2025-48585"],"modified":"2026-04-17T15:55:28.020024Z","published":"2026-03-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2026-03-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/packages/modules/Profiling/+/1215317dfc1d88a4b5ea47185fb8f10afd1f78b0"}],"affected":[{"package":{"name":"platform/packages/modules/Profiling","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"16-qpr2-next:0"},{"fixed":"16-qpr2-next:2026-03-01"}]}],"versions":["16-qpr2-next"],"ecosystem_specific":{"types":["DoS"],"fixes":["https://android.googlesource.com/platform/packages/modules/Profiling/+/87f9c22235634653a9eec65712c2e2c8d79c7470"],"vanir_signatures":[{"signature_version":"v1","digest":{"function_hash":"321523558177382364429871604740579064008","length":4174},"id":"ASB-A-425360742-27e8b41f","target":{"file":"service/java/com/android/os/profiling/ProfilingService.java","function":"requestProfiling"},"signature_type":"Function","source":"https://android.googlesource.com/platform/packages/modules/Profiling/+/87f9c22235634653a9eec65712c2e2c8d79c7470","deprecated":false},{"signature_version":"v1","digest":{"function_hash":"215514165358721291170112502570823184884","length":266},"id":"ASB-A-425360742-4f4f3fb3","target":{"file":"service/java/com/android/os/profiling/ProfilingService.java","function":"addProfilingTriggers"},"signature_type":"Function","source":"https://android.googlesource.com/platform/packages/modules/Profiling/+/87f9c22235634653a9eec65712c2e2c8d79c7470","deprecated":false},{"signature_version":"v1","digest":{"function_hash":"14413166325762495387442160408739199330","length":365},"id":"ASB-A-425360742-79f16089","target":{"file":"service/java/com/android/os/profiling/ProfilingService.java","function":"removeProfilingTriggers"},"signature_type":"Function","source":"https://android.googlesource.com/platform/packages/modules/Profiling/+/87f9c22235634653a9eec65712c2e2c8d79c7470","deprecated":false},{"signature_version":"v1","digest":{"function_hash":"127244509170297809173688316334052686517","length":120},"id":"ASB-A-425360742-9be7b53d","target":{"file":"service/java/com/android/os/profiling/ProfilingService.java","function":"addAllProfilingTriggers"},"signature_type":"Function","source":"https://android.googlesource.com/platform/packages/modules/Profiling/+/87f9c22235634653a9eec65712c2e2c8d79c7470","deprecated":false},{"signature_version":"v1","digest":{"function_hash":"91777179240609164907840462464668068850","length":286},"id":"ASB-A-425360742-9fdfd608","target":{"file":"service/java/com/android/os/profiling/ProfilingService.java","function":"processTrigger"},"signature_type":"Function","source":"https://android.googlesource.com/platform/packages/modules/Profiling/+/87f9c22235634653a9eec65712c2e2c8d79c7470","deprecated":false},{"signature_version":"v1","digest":{"function_hash":"61808808560059721740538028529609307069","length":94},"id":"ASB-A-425360742-a939ab96","target":{"file":"service/java/com/android/os/profiling/ProfilingService.java","function":"clearProfilingTriggers"},"signature_type":"Function","source":"https://android.googlesource.com/platform/packages/modules/Profiling/+/87f9c22235634653a9eec65712c2e2c8d79c7470","deprecated":false},{"signature_version":"v1","digest":{"threshold":0.9,"line_hashes":["1443997449247547392328445191436651134","299753554071673260083944103332722193332","19357854165115454005956090383749192542","264733616998673788381717929590350452121","302295898579960474095833221915701420851","205927227429974118677835560911109069309","68965286266530862647320182887596871609","332847177147234078800189343667855946728","118622279888701845377170432046327993971","211103852024376182614726808067985300070","3575422574010173698510180626297893722","336121306051143510959087795446156085538","177047789963305690732170022758586226093","89722901871748807254102636604135529386","145808345822199914366531122116822695576","131378571848232960758983189678112494446","204049043409631006142729646690359217590","69543443552339246284730219428936584811","129832443862921613339235334856090452394","232426969846929706276720908728563897099","3575422574010173698510180626297893722","336121306051143510959087795446156085538","177047789963305690732170022758586226093","89722901871748807254102636604135529386","272618058369084808638029541390553852890","263989670507440344376819215704286459219","87570287489704043499438130200209697820","26764267502432394694896700235130399819","240739508362518075911916930751757528460","331780794721347435832115488064505719223","334520242175181877130615011050989002811","68637563610335302267954725179762463785","20832428796681402718388275441806850805","105848367141771924214670852678519406530","55307397755961369855672997840078651948","217358413069242719901048760151548669958","171625275022484512755950024324166621742","247993869435595039691682233183051132967","188070015766614865613950555435226225115","306539845890077555289234142541471266582","220702503989754279975229025857593713997","49477899739719288034899661564456277259","22961471040321707224135586798804265606","162947925863462698669000096009376678913","318883655712075619416032714677450641851","206265939000422764043343567377084948493","208282817053583097602256392897690351734","52438918299293292957789519872143153944","55943278476452530877681661488885150534","209565695128543107281720988937847020418","338061051352038463886100363569769819484","150563182703371249179137705205288309297","214169410811608823047261927562100891263","66853216234417912716623613926253833155","148101704596061384401297742203519288710","196365946482796192971765270304395735809","71678394544646883164253142384265364409","191950232560865723021475823686979397093","250574102737248484482695690556964724486","218033585863409006541609825947276410625","81858748330779818609224946187512459799","151385359903322923974193673137795416929"]},"id":"ASB-A-425360742-f9fec9d4","target":{"file":"service/java/com/android/os/profiling/ProfilingService.java"},"signature_type":"Line","source":"https://android.googlesource.com/platform/packages/modules/Profiling/+/87f9c22235634653a9eec65712c2e2c8d79c7470","deprecated":false}],"spl":"2026-03-01","severity":"High"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-425360742.json"}},{"package":{"name":"platform/packages/modules/Profiling","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"16:0"},{"fixed":"16:2026-03-01"}]}],"versions":["16"],"ecosystem_specific":{"types":["DoS"],"fixes":["https://android.googlesource.com/platform/packages/modules/Profiling/+/aef103928d0380e0a4bb24e13768a844e9698413"],"vanir_signatures":[{"signature_version":"v1","digest":{"function_hash":"215514165358721291170112502570823184884","length":266},"id":"ASB-A-425360742-24f87ee7","target":{"file":"service/java/com/android/os/profiling/ProfilingService.java","function":"addProfilingTriggers"},"signature_type":"Function","source":"https://android.googlesource.com/platform/packages/modules/Profiling/+/aef103928d0380e0a4bb24e13768a844e9698413","deprecated":false},{"signature_version":"v1","digest":{"threshold":0.9,"line_hashes":["1443997449247547392328445191436651134","299753554071673260083944103332722193332","19357854165115454005956090383749192542","227558048671989212844273390426026427042","206265939000422764043343567377084948493","208282817053583097602256392897690351734","52438918299293292957789519872143153944","268040839556110373133218334057087183159","275576469358475651592904582088286549755","66853216234417912716623613926253833155","148101704596061384401297742203519288710","196365946482796192971765270304395735809","71678394544646883164253142384265364409","191950232560865723021475823686979397093","250574102737248484482695690556964724486"]},"id":"ASB-A-425360742-2634a478","target":{"file":"service/java/com/android/os/profiling/ProfilingService.java"},"signature_type":"Line","source":"https://android.googlesource.com/platform/packages/modules/Profiling/+/aef103928d0380e0a4bb24e13768a844e9698413","deprecated":false},{"signature_version":"v1","digest":{"function_hash":"61808808560059721740538028529609307069","length":94},"id":"ASB-A-425360742-8e5b3e2e","target":{"file":"service/java/com/android/os/profiling/ProfilingService.java","function":"clearProfilingTriggers"},"signature_type":"Function","source":"https://android.googlesource.com/platform/packages/modules/Profiling/+/aef103928d0380e0a4bb24e13768a844e9698413","deprecated":false},{"signature_version":"v1","digest":{"function_hash":"14413166325762495387442160408739199330","length":365},"id":"ASB-A-425360742-d8561815","target":{"file":"service/java/com/android/os/profiling/ProfilingService.java","function":"removeProfilingTriggers"},"signature_type":"Function","source":"https://android.googlesource.com/platform/packages/modules/Profiling/+/aef103928d0380e0a4bb24e13768a844e9698413","deprecated":false}],"spl":"2026-03-01","severity":"High"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-425360742.json"}}],"schema_version":"1.7.5"}