CVE-2026-25274
Received Received - Intake

Memory Corruption in Qualcomm DMA Driver

Vulnerability report for CVE-2026-25274, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: Qualcomm, Inc.

Description

Memory Corruption when processing concurrent DMA buffer allocation and deallocation commands without proper synchronization.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 45 associated CPEs
Vendor Product Version / Range
Qualcomm, Inc. Snapdragon AQT1000
Qualcomm, Inc. Snapdragon Cologne
Qualcomm, Inc. Snapdragon Congo
Qualcomm, Inc. Snapdragon FastConnect 6200
Qualcomm, Inc. Snapdragon FastConnect 6700
Qualcomm, Inc. Snapdragon FastConnect 6800
Qualcomm, Inc. Snapdragon FastConnect 6900
Qualcomm, Inc. Snapdragon FastConnect 7800
Qualcomm, Inc. Snapdragon IQX5121
Qualcomm, Inc. Snapdragon QCA0000
Qualcomm, Inc. Snapdragon QCA2062
Qualcomm, Inc. Snapdragon QCA2064
Qualcomm, Inc. Snapdragon QCA2065
Qualcomm, Inc. Snapdragon QCA2066
Qualcomm, Inc. Snapdragon QCA6391
Qualcomm, Inc. Snapdragon QCA6420
Qualcomm, Inc. Snapdragon QCA6430
Qualcomm, Inc. Snapdragon QCC2073
Qualcomm, Inc. Snapdragon QCC2076
Qualcomm, Inc. Snapdragon QCM5430
Qualcomm, Inc. Snapdragon QCM6490
Qualcomm, Inc. Snapdragon Qualcomm Dragonwing IQ-X
Qualcomm, Inc. Snapdragon Qualcomm FastConnect 8800 Mobile Connectivity System
Qualcomm, Inc. Snapdragon Qualcomm Video Collaboration VC3 Platform
Qualcomm, Inc. Snapdragon SC8380XP
Qualcomm, Inc. Snapdragon Snapdragon 7c+ Gen 3 Compute
Qualcomm, Inc. Snapdragon Snapdragon 8c Compute Platform "Poipu Lite"
Qualcomm, Inc. Snapdragon Snapdragon 8cx Compute Platform
Qualcomm, Inc. Snapdragon Snapdragon 8cx Gen 2 5G Compute Platform "Poipu Pro"
Qualcomm, Inc. Snapdragon Snapdragon 8cx Gen 3 Compute Platform
Qualcomm, Inc. Snapdragon Snapdragon X2 Elite
Qualcomm, Inc. Snapdragon WCD9340
Qualcomm, Inc. Snapdragon WCD9341
Qualcomm, Inc. Snapdragon WCD9370
Qualcomm, Inc. Snapdragon WCD9375
Qualcomm, Inc. Snapdragon WCD9378C
Qualcomm, Inc. Snapdragon WCD9380
Qualcomm, Inc. Snapdragon WCD9385
Qualcomm, Inc. Snapdragon WSA8810
Qualcomm, Inc. Snapdragon WSA8815
Qualcomm, Inc. Snapdragon WSA8830
Qualcomm, Inc. Snapdragon WSA8835
Qualcomm, Inc. Snapdragon WSA8840
Qualcomm, Inc. Snapdragon WSA8845
Qualcomm, Inc. Snapdragon WSA8845H

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-416 The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a memory corruption vulnerability in Qualcomm Snapdragon devices caused by improper synchronization during concurrent DMA buffer allocation and deallocation. This can lead to system instability or arbitrary code execution.

Detection Guidance

This vulnerability involves memory corruption during concurrent DMA buffer operations. Detection requires analyzing system logs for memory allocation errors or crashes during DMA operations. Check for Qualcomm Snapdragon device logs for DMA-related errors or kernel panics.

Impact Analysis

An attacker could exploit this to crash your device, gain unauthorized access, or execute malicious code. It primarily affects devices using Qualcomm Snapdragon processors with improper DMA handling.

Compliance Impact

This vulnerability could lead to memory corruption during DMA operations, potentially causing unauthorized access or data leaks. Such issues may violate data protection requirements under GDPR (e.g., integrity and confidentiality principles) and HIPAA (e.g., safeguarding protected health information).

Mitigation Strategies

Apply vendor-provided patches or updates for Qualcomm Snapdragon devices to address memory corruption in DMA buffer handling. Ensure proper synchronization mechanisms are implemented in concurrent DMA operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-25274. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart