CVE-2025-27701 Information

Description

In the function process_crypto_cmd the values of ptrs[i] can be potentially equal to NULL which is valid value after calling slice_map_array(). Later this values will be derefenced without prior NULL check which can lead to local Temporary DoS or OOB Read leading to information disclosure.

Reference

https://source.android.com/security/bulletin/pixel/2025-05-01

Share on: