Qualcomm Various Chipsets Use-After-Free Vulnerability in Computer Vision via IOCTL Calls

Vulnerability

A use-after-free vulnerability has been identified in Qualcomm chipsets, allowing memory corruption by invoking IOCTL calls from user-space to kernel-space. This vulnerability arises while handling session errors, potentially leading to unauthorized memory access or manipulation.

Impact

Exploitation of this vulnerability causes memory corruption, which can be leveraged to manipulate program execution or access unauthorized memory regions.

Remediation

Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm February 2025 Security Bulletin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.