CVE-2026-0142
published 2026-06-16CVE-2026-0142: In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure…
PriorityP423
EPSS
0.07%
0.0th percentile
In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android avb_rsa.c iavb_parse_key_data out-of-bounds
vuldb·2026-06-16
CVE-2026-0142 [LOW] Google Android avb_rsa.c iavb_parse_key_data out-of-bounds
A vulnerability, which was classified as critical, has been found in Google Android. This impacts the function iavb_parse_key_data of the file avb_rsa.c. The manipulation leads to out-of-bounds read.
This vulnerability is referenced as CVE-2026-0142. The attack can only be performed from a local environment. No exploit is available.
GHSA
In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation.
ghsa_unreviewed·2026-06-16
CVE-2026-0142 [LOW] CWE-20 In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation.
In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-16
Published