CVE-2026-25271
Analyzed Analyzed - Analysis Complete

Memory Corruption in Qualcomm Chipset Firmware

Vulnerability report for CVE-2026-25271, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-06

Last updated on: 2026-07-07

Assigner: Qualcomm, Inc.

Description

Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-06
Last Modified
2026-07-07
Generated
2026-07-27
AI Q&A
2026-07-07
EPSS Evaluated
2026-07-25
NVD

Affected Vendors & Products

Showing 21 associated CPEs
Vendor Product Version / Range
qualcomm cologne_firmware *
qualcomm fastconnect_6900_firmware *
qualcomm fastconnect_7800_firmware *
qualcomm iqx5121_firmware *
qualcomm iqx7181_firmware *
qualcomm qca0000_firmware *
qualcomm sc8380xp_firmware *
qualcomm wcd9378c_firmware *
qualcomm wcd9380_firmware *
qualcomm wcd9385_firmware *
qualcomm wsa8840_firmware *
qualcomm wsa8845_firmware *
qualcomm wsa8845h_firmware *
qualcomm x2000077_firmware *
qualcomm x2000086_firmware *
qualcomm x2000090_firmware *
qualcomm x2000092_firmware *
qualcomm x2000094_firmware *
qualcomm xg101002_firmware *
qualcomm xg101032_firmware *
qualcomm xg101039_firmware *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a memory corruption issue that occurs when processing asynchronous input parameters. It happens because of improper handling of modified values between the time they are checked and the time they are used.

Impact Analysis

The vulnerability has a high severity with a CVSS base score of 7.8, indicating it can lead to significant impacts including high confidentiality, integrity, and availability losses. Exploiting this memory corruption could allow an attacker with low privileges and local access to cause serious damage such as unauthorized data access, data modification, or denial of service.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-25271. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart