CVE-2025-21468

HIGH EPSS 0.5%
Published May 6, 20251y ago · Modified Jun 17, 20261w ago
7.8 CVSS 3.1
High
Find Similar
Published May 6, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
0.5% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-787 Out-of-bounds Write Memory Safety

Affected Products 302

VendorProductVersionRange
qualcommar8035_firmware*any
qualcommar8035*any
qualcommcsra6620_firmware*any
qualcommcsra6620*any
qualcommcsra6640_firmware*any
qualcommcsra6640*any
qualcommfastconnect_6200_firmware*any
qualcommfastconnect_6200*any
qualcommfastconnect_6700_firmware*any
qualcommfastconnect_6700*any
qualcommwcd9380_firmware*any
qualcommwcd9380*any
qualcommwcd9385_firmware*any
qualcommwcd9385*any
qualcommwcd9390_firmware*any
qualcommwcd9390*any
qualcommwcd9395_firmware*any
qualcommwcd9395*any
qualcommwcn3910_firmware*any
qualcommwcn3910*any
qualcommwcn3950_firmware*any
qualcommwcn3950*any
qualcommwcn3980_firmware*any
qualcommwcn3980*any
qualcommwcn3988_firmware*any
qualcommwcn3988*any
qualcommwcn3990_firmware*any
qualcommwcn3990*any
qualcommwcn6450_firmware*any
qualcommwcn6450*any
qualcommwcn6650_firmware*any
qualcommwcn6650*any
qualcommwcn6740_firmware*any
qualcommwcn6740*any
qualcommwcn6755_firmware*any
qualcommwcn6755*any
qualcommwcn7750_firmware*any
qualcommwcn7750*any
qualcommqca6595_firmware*any
qualcommqca6595*any
qualcommqca6595au_firmware*any
qualcommqca6595au*any
qualcommqca6696_firmware*any
qualcommqca6696*any
qualcommqca6698aq_firmware*any
qualcommqca6698aq*any
qualcommqca8081_firmware*any
qualcommqca8081*any
qualcommqca8337_firmware*any
qualcommqca8337*any
qualcommqca9377_firmware*any
qualcommqca9377*any
qualcommqcm4490_firmware*any
qualcommqcm4490*any
qualcommqcm5430_firmware*any
qualcommqcm5430*any
qualcommqcm6490_firmware*any
qualcommqcm6490*any
qualcommqcm8550_firmware*any
qualcommqcm8550*any
qualcommqcn6024_firmware*any
qualcommqcn6024*any
qualcommqcn9011_firmware*any
qualcommqcn9011*any
qualcommqcn9012_firmware*any
qualcommqcn9012*any
qualcommqcn9024_firmware*any
qualcommqcn9024*any
qualcommqcn9274_firmware*any
qualcommqcn9274*any
qualcommqcs410_firmware*any
qualcommqcs410*any
qualcommqcs4490_firmware*any
qualcommqcs4490*any
qualcommqcs5430_firmware*any
qualcommqcs5430*any
qualcommqcs610_firmware*any
qualcommqcs610*any
qualcommqcs615_firmware*any
qualcommqcs615*any
qualcommqcs6490_firmware*any
qualcommqcs6490*any
qualcommqcs7230_firmware*any
qualcommqcs7230*any
qualcommqcs8250_firmware*any
qualcommqcs8250*any
qualcommqcs8300_firmware*any
qualcommqcs8300*any
qualcommqcs8550_firmware*any
qualcommqcs8550*any
qualcommqcs9100_firmware*any
qualcommqcs9100*any
qualcommqmp1000_firmware*any
qualcommqmp1000*any
qualcommqrb5165m_firmware*any
qualcommqrb5165m*any
qualcommqrb5165n_firmware*any
qualcommqrb5165n*any
qualcommqsm8350_firmware*any
qualcommqsm8350*any
qualcommvideo_collaboration_vc1_platform_firmware*any
qualcommvideo_collaboration_vc1_platform*any
qualcommvideo_collaboration_vc3_platform_firmware*any
qualcommvideo_collaboration_vc3_platform*any
qualcommqca6574au_firmware*any
qualcommqca6574au*any
qualcommqca6574a_firmware*any
qualcommqca6574a*any
qualcommqca6574_firmware*any
qualcommqca6574*any
qualcommqca6564au_firmware*any
qualcommqca6564au*any
qualcommqca6564a_firmware*any
qualcommqca6564a*any
qualcommqca6391_firmware*any
qualcommqca6391*any
qualcommqca6174a_firmware*any
qualcommqca6174a*any
qualcommqam8295p_firmware*any
qualcommqam8295p*any
qualcommmdm9628_firmware*any
qualcommmdm9628*any
qualcommflight_rb5_5g_firmware*any
qualcommflight_rb5_5g*any
qualcommfastconnect_7800_firmware*any
qualcommfastconnect_7800*any
qualcommfastconnect_6900_firmware*any
qualcommfastconnect_6900*any
qualcommwsa8845h_firmware*any
qualcommwsa8845h*any
qualcommwsa8845_firmware*any
qualcommwsa8845*any
qualcommwsa8840_firmware*any
qualcommwsa8840*any
qualcommwsa8835_firmware*any
qualcommwsa8835*any
qualcommwsa8832_firmware*any
qualcommwsa8832*any
qualcommwsa8830_firmware*any
qualcommwsa8830*any
qualcommwsa8815_firmware*any
qualcommwsa8815*any
qualcommwsa8810_firmware*any
qualcommwsa8810*any
qualcommwcn7881_firmware*any
qualcommwcn7881*any
qualcommwcn7880_firmware*any
qualcommwcn7880*any
qualcommwcn7861_firmware*any
qualcommwcn7861*any
qualcommwcn7860_firmware*any
qualcommwcn7860*any
qualcommvideo_collaboration_vc5_platform_firmware*any
qualcommvideo_collaboration_vc5_platform*any
qualcommrobotics_rb2_firmware*any
qualcommrobotics_rb2*any
qualcommrobotics_rb5_firmware*any
qualcommrobotics_rb5*any
qualcommsa4150p_firmware*any
qualcommsa4150p*any
qualcommsa4155p_firmware*any
qualcommsa4155p*any
qualcommsa6145p_firmware*any
qualcommsa6145p*any
qualcommsa6150p_firmware*any
qualcommsa6150p*any
qualcommsa6155p_firmware*any
qualcommsa6155p*any
qualcommsa8145p_firmware*any
qualcommsa8145p*any
qualcommsa8150p_firmware*any
qualcommsa8150p*any
qualcommsa8155p_firmware*any
qualcommsa8155p*any
qualcommsa8195p_firmware*any
qualcommsa8195p*any
qualcommsa8295p_firmware*any
qualcommsa8295p*any
qualcommsa8530p_firmware*any
qualcommsa8530p*any
qualcommsa8540p_firmware*any
qualcommsa8540p*any
qualcommsa9000p_firmware*any
qualcommsa9000p*any
qualcommsd_8_gen1_5g_firmware*any
qualcommsd_8_gen1_5g*any
qualcommsd888_firmware*any
qualcommsd888*any
qualcommsdx61_firmware*any
qualcommsdx61*any
qualcommsg8275p_firmware*any
qualcommsg8275p*any
qualcommsm6370_firmware*any
qualcommsm6370*any
qualcommsm6650_firmware*any
qualcommsm6650*any
qualcommsm6650p_firmware*any
qualcommsm6650p*any
qualcommsm7315_firmware*any
qualcommsm7315*any
qualcommsm7325p_firmware*any
qualcommsm7325p*any
qualcommsm7635_firmware*any
qualcommsm7635*any
qualcommsm7675_firmware*any
qualcommsm7675*any
qualcommsm7675p_firmware*any
qualcommsm7675p*any
qualcommsm8550p_firmware*any
qualcommsm8550p*any
qualcommsm8635_firmware*any
qualcommsm8635*any
qualcommsm8635p_firmware*any
qualcommsm8635p*any
qualcommsm8650q_firmware*any
qualcommsm8650q*any
qualcommsm8735_firmware*any
qualcommsm8735*any
qualcommsm8750_firmware*any
qualcommsm8750*any
qualcommsm8750p_firmware*any
qualcommsm8750p*any
qualcommsmart_audio_400_firmware*any
qualcommsmart_audio_400*any
qualcommsnapdragon_4_gen_1_mobile_firmware*any
qualcommsnapdragon_4_gen_1_mobile*any
qualcommsnapdragon_4_gen_2_mobile_firmware*any
qualcommsnapdragon_4_gen_2_mobile*any
qualcommsnapdragon_480_5g_mobile_firmware*any
qualcommsnapdragon_480_5g_mobile*any
qualcommsnapdragon_480\+_5g_mobile_firmware*any
qualcommsnapdragon_480\+_5g_mobile*any
qualcommsnapdragon_695_5g_mobile_firmware*any
qualcommsnapdragon_695_5g_mobile*any
qualcommsnapdragon_778g_5g_mobile_firmware*any
qualcommsnapdragon_778g_5g_mobile*any
qualcommsnapdragon_778g\+_5g_mobile_firmware*any
qualcommsnapdragon_778g\+_5g_mobile*any
qualcommsnapdragon_780g_5g_mobile_firmware*any
qualcommsnapdragon_780g_5g_mobile*any
qualcommsnapdragon_782g_mobile_firmware*any
qualcommsnapdragon_782g_mobile*any
qualcommsnapdragon_7c\+_gen_3_compute_firmware*any
qualcommsnapdragon_7c\+_gen_3_compute*any
qualcommsnapdragon_8_gen_1_mobile_firmware*any
qualcommsnapdragon_8_gen_1_mobile*any
qualcommsnapdragon_8_gen_2_mobile_firmware*any
qualcommsnapdragon_8_gen_2_mobile*any
qualcommsnapdragon_8_gen_3_mobile_firmware*any
qualcommsnapdragon_8_gen_3_mobile*any
qualcommsnapdragon_8\+_gen_1_mobile_firmware*any
qualcommsnapdragon_8\+_gen_1_mobile*any
qualcommsnapdragon_8\+_gen_2_mobile_firmware*any
qualcommsnapdragon_8\+_gen_2_mobile*any
qualcommsnapdragon_888_5g_mobile_firmware*any
qualcommsnapdragon_888_5g_mobile*any
qualcommsnapdragon_888\+_5g_mobile_firmware*any
qualcommsnapdragon_888\+_5g_mobile*any
qualcommsnapdragon_ar1_gen_1_firmware*any
qualcommsnapdragon_ar1_gen_1*any
qualcommsnapdragon_ar2_gen_1_firmware*any
qualcommsnapdragon_ar2_gen_1*any
qualcommsnapdragon_auto_5g_modem-rf_firmware*any
qualcommsnapdragon_auto_5g_modem-rf*any
qualcommsnapdragon_w5\+_gen_1_wearable_firmware*any
qualcommsnapdragon_w5\+_gen_1_wearable*any
qualcommsnapdragon_x12_lte_modem_firmware*any
qualcommsnapdragon_x12_lte_modem*any
qualcommsnapdragon_x62_5g_modem-rf_firmware*any
qualcommsnapdragon_x62_5g_modem-rf*any
qualcommsnapdragon_x65_5g_modem-rf_firmware*any
qualcommsnapdragon_x65_5g_modem-rf*any
qualcommssg2115p_firmware*any
qualcommssg2115p*any
qualcommssg2125p_firmware*any
qualcommssg2125p*any
qualcommsw5100_firmware*any
qualcommsw5100*any
qualcommsw5100p_firmware*any
qualcommsw5100p*any
qualcommsxr1230p_firmware*any
qualcommsxr1230p*any
qualcommsxr2230p_firmware*any
qualcommsxr2230p*any
qualcommsxr2250p_firmware*any
qualcommsxr2250p*any
qualcommsxr2330p_firmware*any
qualcommsxr2330p*any
qualcommtalynplus_firmware*any
qualcommtalynplus*any
qualcommvision_intelligence_400_firmware*any
qualcommvision_intelligence_400*any
qualcommwcd9335_firmware*any
qualcommwcd9335*any
qualcommwcd9341_firmware*any
qualcommwcd9341*any
qualcommwcd9370_firmware*any
qualcommwcd9370*any
qualcommwcd9375_firmware*any
qualcommwcd9375*any
qualcommwcd9378_firmware*any
qualcommwcd9378*any

References 1

  • docs.qualcomm.com https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2025-bulletin.html
    PatchVendor Advisory

Remediation

  • docs.qualcomm.com https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2025-bulletin.html
    PatchVendor Advisory