CVE-2025-21456
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-08-06

Last updated on: 2025-08-20

Assigner: Qualcomm, Inc.

Description
Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-08-06
Last Modified
2025-08-20
Generated
2026-05-27
AI Q&A
2025-08-06
EPSS Evaluated
2026-05-25
NVD
EUVD
Affected Vendors & Products
Showing 128 associated CPEs
Vendor Product Version / Range
qualcomm ar8035_firmware *
qualcomm ar8035 *
qualcomm c-v2x_9150_firmware *
qualcomm c-v2x_9150 *
qualcomm fastconnect_6900_firmware *
qualcomm fastconnect_6900 *
qualcomm fastconnect_7800_firmware *
qualcomm fastconnect_7800 *
qualcomm qam8255p_firmware *
qualcomm qam8255p *
qualcomm qam8295p_firmware *
qualcomm qam8295p *
qualcomm qam8650p_firmware *
qualcomm qam8650p *
qualcomm qam8775p_firmware *
qualcomm qam8775p *
qualcomm qca6174a_firmware *
qualcomm qca6174a *
qualcomm qca6574au_firmware *
qualcomm qca6574au *
qualcomm qca6584au_firmware *
qualcomm qca6584au *
qualcomm qca6696_firmware *
qualcomm qca6696 *
qualcomm qca6698aq_firmware *
qualcomm qca6698aq *
qualcomm qca6797aq_firmware *
qualcomm qca6797aq *
qualcomm qca8081_firmware *
qualcomm qca8081 *
qualcomm qca8337_firmware *
qualcomm qca8337 *
qualcomm qcc710_firmware *
qualcomm qcc710 *
qualcomm qcn6224_firmware *
qualcomm qcn6224 *
qualcomm qcn6274_firmware *
qualcomm qcn6274 *
qualcomm qcs410_firmware *
qualcomm qcs410 *
qualcomm qcs610_firmware *
qualcomm qcs610 *
qualcomm qfw7114_firmware *
qualcomm qfw7114 *
qualcomm qfw7124_firmware *
qualcomm qfw7124 *
qualcomm video_collaboration_vc1_platform_firmware *
qualcomm video_collaboration_vc1_platform *
qualcomm video_collaboration_vc3_platform_firmware *
qualcomm video_collaboration_vc3_platform *
qualcomm sa6145p_firmware *
qualcomm sa6145p *
qualcomm sa6150p_firmware *
qualcomm sa6150p *
qualcomm sa6155p_firmware *
qualcomm sa6155p *
qualcomm sa7255p_firmware *
qualcomm sa7255p *
qualcomm sa7775p_firmware *
qualcomm sa7775p *
qualcomm sa8145p_firmware *
qualcomm sa8145p *
qualcomm sa8150p_firmware *
qualcomm sa8150p *
qualcomm sa8155p_firmware *
qualcomm sa8155p *
qualcomm sa8195p_firmware *
qualcomm sa8195p *
qualcomm sa8255p_firmware *
qualcomm sa8255p *
qualcomm sa8295p_firmware *
qualcomm sa8295p *
qualcomm sa8530p_firmware *
qualcomm sa8530p *
qualcomm sa8540p_firmware *
qualcomm sa8540p *
qualcomm sa8620p_firmware *
qualcomm sa8620p *
qualcomm sa8650p_firmware *
qualcomm sa8650p *
qualcomm sa8775p_firmware *
qualcomm sa8775p *
qualcomm sa9000p_firmware *
qualcomm sa9000p *
qualcomm snapdragon_888_5g_mobile_platform_firmware *
qualcomm snapdragon_888_5g_mobile_platform *
qualcomm snapdragon_888\+_5g_mobile_platform_\(sm8350-ac\)_firmware *
qualcomm snapdragon_888\+_5g_mobile_platform_\(sm8350-ac\) *
qualcomm snapdragon_auto_5g_modem-rf_gen_2_firmware *
qualcomm snapdragon_auto_5g_modem-rf_gen_2 *
qualcomm snapdragon_w5\+_gen_1_wearable_platform_firmware *
qualcomm snapdragon_w5\+_gen_1_wearable_platform *
qualcomm snapdragon_x72_5g_modem-rf_system_firmware *
qualcomm snapdragon_x72_5g_modem-rf_system *
qualcomm snapdragon_x75_5g_modem-rf_system_firmware *
qualcomm snapdragon_x75_5g_modem-rf_system *
qualcomm sw5100_firmware *
qualcomm sw5100 *
qualcomm sw5100p_firmware *
qualcomm sw5100p *
qualcomm wcd9340_firmware *
qualcomm wcd9340 *
qualcomm wcd9341_firmware *
qualcomm wcd9341 *
qualcomm wcd9370_firmware *
qualcomm wcd9370 *
qualcomm wcd9380_firmware *
qualcomm wcd9380 *
qualcomm wcd9385_firmware *
qualcomm wcd9385 *
qualcomm wcn3660b_firmware *
qualcomm wcn3660b *
qualcomm wcn3680b_firmware *
qualcomm wcn3680b *
qualcomm wcn3950_firmware *
qualcomm wcn3950 *
qualcomm wcn3980_firmware *
qualcomm wcn3980 *
qualcomm wcn3988_firmware *
qualcomm wcn3988 *
qualcomm wsa8810_firmware *
qualcomm wsa8810 *
qualcomm wsa8815_firmware *
qualcomm wsa8815 *
qualcomm wsa8830_firmware *
qualcomm wsa8830 *
qualcomm wsa8835_firmware *
qualcomm wsa8835 *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-416 The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a memory corruption issue that occurs when processing an IOCTL command. It happens specifically when multiple threads concurrently call to map or unmap a buffer, leading to unsafe memory operations.


How can this vulnerability impact me? :

The vulnerability can lead to severe impacts including high confidentiality, integrity, and availability risks. Exploiting this memory corruption could allow an attacker with limited privileges to cause system crashes, execute arbitrary code, or gain unauthorized access to sensitive information.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart