---
id: CVE-2025-36917
title: >-
  In SwDcpItg of up_L2commonPdcpSecurity.cpp, there is a possible denial of
  service due to an incorrect bounds check
summary: >-
  In SwDcpItg of up_L2commonPdcpSecurity.cpp, there is a possible denial of
  service due to an incorrect bounds check. This could lead to remote denial of
  service with no additional execution privileges needed. User interaction is
  not neede…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-120
vendor: google
product: android
affected:
  - android
published: '2025-12-11'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:10:00.223'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-36917'
references:
  - url: 'https://source.android.com/security/bulletin/pixel/2025-12-01'
    label: dsap-vuln-management@google.com
tags:
  - nvd
epss: 0.00302
epssPercentile: 0.20679
ingestedAt: '2026-09-30T17:13:20.760Z'
---

## Overview

In SwDcpItg of up_L2commonPdcpSecurity.cpp, there is a possible denial of service due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

## Affected

- `android`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
