CVE-2025-59617
Analyzed Analyzed - Analysis Complete

Memory Corruption in Qualcomm Chipset Drivers

Vulnerability report for CVE-2025-59617, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-06

Last updated on: 2026-07-07

Assigner: Qualcomm, Inc.

Description

Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-06
Last Modified
2026-07-07
Generated
2026-07-27
AI Q&A
2026-07-07
EPSS Evaluated
2026-07-25
NVD

Affected Vendors & Products

Showing 48 associated CPEs
Vendor Product Version / Range
qualcomm fastconnect_6700_firmware *
qualcomm fastconnect_6900_firmware *
qualcomm fastconnect_7800_firmware *
qualcomm molokai_firmware *
qualcomm orne_firmware *
qualcomm pandeiro_firmware *
qualcomm qcm5430_firmware *
qualcomm qcm6490_firmware *
qualcomm qmp1000_firmware *
qualcomm qmp2001_firmware *
qualcomm video_collaboration_vc3_platform_firmware *
qualcomm sc8380xp_firmware *
qualcomm sd865_5g_firmware *
qualcomm sm6850_firmware *
qualcomm sm8845p_firmware *
qualcomm snapdragon_460_mobile_platform_firmware *
qualcomm snapdragon_662_mobile_platform_firmware *
qualcomm snapdragon_8_elite_gen_5_firmware *
qualcomm snapdragon_ar1_gen_1_platform_firmware *
qualcomm snapdragon_xr2_5g_platform_firmware *
qualcomm snapdragon_xr2+_gen_1_platform_firmware *
qualcomm sxr2230p_firmware *
qualcomm sxr2250p_firmware *
qualcomm wcd9370_firmware *
qualcomm wcd9375_firmware *
qualcomm wcd9378_firmware *
qualcomm wcd9380_firmware *
qualcomm wcd9385_firmware *
qualcomm wcd9395_firmware *
qualcomm wcn3950_firmware *
qualcomm wcn3988_firmware *
qualcomm wcn6450_firmware *
qualcomm wcn7760_firmware *
qualcomm wcn7860_firmware *
qualcomm wcn7861_firmware *
qualcomm wcn7880_firmware *
qualcomm wcn7881_firmware *
qualcomm wsa8810_firmware *
qualcomm wsa8815_firmware *
qualcomm wsa8830_firmware *
qualcomm wsa8832_firmware *
qualcomm wsa8835_firmware *
qualcomm wsa8840_firmware *
qualcomm wsa8845_firmware *
qualcomm wsa8845h_firmware *
qualcomm wsa8850_firmware *
qualcomm wsa8850w_firmware *
qualcomm wsa8855c_firmware *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-416 The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves memory corruption that occurs when multiple IOCTL calls are processed using the same buffer file descriptor as input.

Impact Analysis

The vulnerability can lead to memory corruption which may result in partial loss of confidentiality, high impact on integrity, and low impact on availability according to its CVSS score.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-59617. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart