CVE-2026-25262
Received Received - Intake

Primary Bootloader Memory Corruption via Malicious ELF File

Vulnerability report for CVE-2026-25262, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: Qualcomm, Inc.

Description

Memory corruption while processing a crafted ELF file in the Primary Bootloader.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-123 Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a memory corruption issue that occurs when the Primary Bootloader processes a specially crafted ELF file. It can lead to unauthorized code execution or system crashes during the boot process.

Impact Analysis

An attacker could exploit this to gain control over the device during boot, potentially leading to data theft, malware installation, or denial of service. It primarily affects systems using the vulnerable bootloader.

Compliance Impact

This vulnerability involves memory corruption in a bootloader, which could lead to unauthorized code execution or data exposure. Such issues may violate compliance requirements under GDPR (data protection) or HIPAA (health data security) if exploited to access sensitive information. However, specific compliance impacts depend on system configuration and deployment context.

Mitigation Strategies

Apply patches or updates from Qualcomm if available. Avoid processing untrusted ELF files in the Primary Bootloader. Monitor Qualcomm security advisories for fixes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-25262. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart