CVE Vulnerabilities

CVE-2025-0081

Use of Uninitialized Variable

Published: Aug 26, 2025 | Modified: Sep 02, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In dng_lossless_decoder::HuffDecode of dng_lossless_jpeg.cpp, there is a possible way to cause a crash due to uninitialized data. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

Weakness

The code uses a variable that has not been initialized, leading to unpredictable or unintended results.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle12.0 (including)12.0 (including)
AndroidGoogle12.1 (including)12.1 (including)
AndroidGoogle13.0 (including)13.0 (including)
AndroidGoogle14.0 (including)14.0 (including)
AndroidGoogle15.0 (including)15.0 (including)

Potential Mitigations

References