Denial of Service Vulnerability in DNG SDK by Android
CVE-2025-0081
Currently unrated
What is CVE-2025-0081?
The DNG SDK suffers from a vulnerability located in the dng_lossless_decoder::HuffDecode function. This issue arises due to uninitialized data handling, which could allow an attacker to induce a crash in the DNG processing functionality. Importantly, this vulnerability does not require user interaction nor additional execution privileges, enabling potential remote denial of service attacks. Proper validation and initialization of data can mitigate the risks associated with this issue.
Affected Version(s)
Android 15
Android 14
Android 13