cbcvebase.
CVE-2025-20751
published 2025-12-02

CVE-2025-20751: In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base…

medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01661195; Issue ID: MSV-4297.

Affected

2 ranges
VendorProductVersion rangeFixed in
googleandroid
keraskeras>= 3.0.0 < 3.9.03.9.0

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.3HIGH