CVE-2025-27037
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-24

Last updated on: 2025-09-25

Assigner: Qualcomm, Inc.

Description
Memory corruption while processing config_dev IOCTL when camera kernel driver drops its reference to CPU buffers.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-24
Last Modified
2025-09-25
Generated
2026-05-07
AI Q&A
2025-09-24
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 74 associated CPEs
Vendor Product Version / Range
qualcomm fastconnect_6800_firmware *
qualcomm fastconnect_6800 *
qualcomm fastconnect_6900_firmware *
qualcomm fastconnect_6900 *
qualcomm fastconnect_7800_firmware *
qualcomm fastconnect_7800 *
qualcomm qam8295p_firmware *
qualcomm qam8295p *
qualcomm qca6391_firmware *
qualcomm qca6391 *
qualcomm qca6426_firmware *
qualcomm qca6426 *
qualcomm qca6436_firmware *
qualcomm qca6436 *
qualcomm qca6574au_firmware *
qualcomm qca6574au *
qualcomm qca6696_firmware *
qualcomm qca6696 *
qualcomm qcn9074_firmware *
qualcomm qcn9074 *
qualcomm sa6145p_firmware *
qualcomm sa6145p *
qualcomm sa6150p_firmware *
qualcomm sa6150p *
qualcomm sa6155p_firmware *
qualcomm sa6155p *
qualcomm sa8145p_firmware *
qualcomm sa8145p *
qualcomm sa8150p_firmware *
qualcomm sa8150p *
qualcomm sa8155p_firmware *
qualcomm sa8155p *
qualcomm sa8195p_firmware *
qualcomm sa8195p *
qualcomm sa8295p_firmware *
qualcomm sa8295p *
qualcomm sd865_5g_firmware *
qualcomm sd865_5g *
qualcomm snapdragon_8_gen_1_mobile_platform_firmware *
qualcomm snapdragon_8_gen_1_mobile_platform *
qualcomm snapdragon_865_5g_mobile_platform_firmware *
qualcomm snapdragon_865_5g_mobile_platform *
qualcomm snapdragon_865\+_5g_mobile_platform_\(sm8250-ab\)_firmware *
qualcomm snapdragon_865\+_5g_mobile_platform_\(sm8250-ab\) *
qualcomm snapdragon_870_5g_mobile_platform_\(sm8250-ac\)_firmware *
qualcomm snapdragon_870_5g_mobile_platform_\(sm8250-ac\) *
qualcomm snapdragon_x55_5g_modem-rf_system_firmware *
qualcomm snapdragon_x55_5g_modem-rf_system *
qualcomm snapdragon_xr2_5g_platform_firmware *
qualcomm snapdragon_xr2_5g_platform *
qualcomm sw5100_firmware *
qualcomm sw5100 *
qualcomm sw5100p_firmware *
qualcomm sw5100p *
qualcomm sxr2130_firmware *
qualcomm sxr2130 *
qualcomm wcd9380_firmware *
qualcomm wcd9380 *
qualcomm wcn3660b_firmware *
qualcomm wcn3660b *
qualcomm wcn3680b_firmware *
qualcomm wcn3680b *
qualcomm wcn3980_firmware *
qualcomm wcn3980 *
qualcomm wcn3988_firmware *
qualcomm wcn3988 *
qualcomm wsa8810_firmware *
qualcomm wsa8810 *
qualcomm wsa8815_firmware *
qualcomm wsa8815 *
qualcomm wsa8830_firmware *
qualcomm wsa8830 *
qualcomm wsa8835_firmware *
qualcomm wsa8835 *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-416 The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :

The vulnerability can lead to high impact consequences including confidentiality, integrity, and availability being compromised. An attacker with limited privileges could exploit this to cause memory corruption, potentially leading to system crashes, data leaks, or unauthorized code execution.


Can you explain this vulnerability to me?

This vulnerability is a memory corruption issue that occurs when the camera kernel driver processes the config_dev IOCTL and improperly drops its reference to CPU buffers. This can lead to unexpected behavior or system instability.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart