Qualcomm WLAN Host Buffer Over-read Vulnerability Allowing Information Disclosure

Vulnerability

A buffer over-read vulnerability has been identified in the WLAN Host component of various chipsets. This vulnerability allows for information disclosure while parsing the OCI Information Element (IE) with invalid length. The issue arises from improper validation of frame content, leading to memory corruption during the processing of management frames.

Impact

Exploitation of this vulnerability causes a buffer over-read, leading to memory corruption and unauthorized information disclosure.

Remediation

Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm February 2025 Security Bulletin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.7
impact
2.5
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.