Qualcomm Products Memory Corruption Vulnerability via IOCTL Calls to Set Mixer Controls

Vulnerability

A memory corruption vulnerability has been identified in various chipsets of Qualcomm products, including those in the Snapdragon series, automotive platforms, and more. This vulnerability arises from improper input validation while processing an IOCTL request to adjust mixer controls, allowing for potential memory corruption.

Impact

Exploitation of this vulnerability leads to memory corruption, which can commonly result in arbitrary code execution or causing a device to crash.

Remediation

Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm May 2025 Security Bulletin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.6
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.