Qualcomm Products Memory Corruption Vulnerability via IOCTL Calls

Vulnerability

A use-after-free vulnerability has been identified in various chipsets of Qualcomm products. This vulnerability arises from memory corruption while processing IOCTL calls to add route entries in the hardware, which can potentially be exploited to cause memory mismanagement issues.

Impact

Exploitation of this vulnerability leads to memory corruption, which can be used to manipulate the program's execution flow, potentially causing a use-after-free condition. This type of vulnerability can often be exploited to execute arbitrary code or cause a denial-of-service condition by crashing the device.

Remediation

Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm April 2025 Security Bulletin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.