Description
In dng_lossless_decoder::HuffDecode of dng_lossless_jpeg.cpp, there is a possible way to cause a crash due to uninitialized data. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Problem types
Denial of service
Product status
15
14
13
12L
12
References
android.googlesource.com/...5af37c97b325dc2956f4a6117c145c2f
source.android.com/security/bulletin/2025-03-01