CVE-2025-27031

HIGH

Qualcomm FastConnect and QCM/QCS Firmware - Memory Corruption via IOCTL

Title source: llm
STIX 2.1

Description

memory corruption while processing IOCTL commands, when the buffer in write loopback mode is accessed after being freed.

Scores

CVSS v3 7.8
EPSS 0.0007
EPSS Percentile 20.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (21)
qualcomm/fastconnect_6700_firmware
qualcomm/fastconnect_6900_firmware
qualcomm/fastconnect_7800_firmware
qualcomm/qcm5430_firmware
qualcomm/qcm6490_firmware
qualcomm/qcs5430_firmware
qualcomm/qcs6490_firmware
qualcomm/sc8380xp_firmware
qualcomm/snapdragon_7c\+_gen_3_compute_firmware
qualcomm/snapdragon_8cx_gen_3_compute_platform_\(sc8280xp-ab\)_firmware
... and 11 more
Published Jun 03, 2025
Tracked Since Feb 18, 2026