CVE-2025-21468

HIGH

Qualcomm AR8035 and Related Firmware - Out-of-bounds Write via Buffer Size Manipulation

Title source: llm
STIX 2.1

Description

Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0007
EPSS Percentile 20.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Products (50)
qualcomm/ar8035_firmware
qualcomm/csra6620_firmware
qualcomm/csra6640_firmware
qualcomm/fastconnect_6200_firmware
qualcomm/fastconnect_6700_firmware
qualcomm/fastconnect_6900_firmware
qualcomm/fastconnect_7800_firmware
qualcomm/flight_rb5_5g_firmware
qualcomm/mdm9628_firmware
qualcomm/qam8295p_firmware
... and 40 more
Published May 06, 2025
Tracked Since Feb 18, 2026