Qualcomm Automotive OS Platform Improper Input Validation Vulnerability Allowing Memory Corruption

Vulnerability

A vulnerability exists in the clock device of the Automotive Software platform based on QNX, where improper input validation may lead to memory corruption. This issue affects several chipsets, including QAM8255P, QAM8295P, QAM8620P, QAM8650P, QAM8775P, SA8255P, SA8295P, SA8540P, SA8620P, SA8650P, SA8770P, SA8775P, and SA9000P.

Impact

Exploitation of this vulnerability can cause memory corruption, potentially leading to arbitrary code execution or causing a denial-of-service condition by crashing the system or application.

Remediation

Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm March 2025 Security Bulletin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
0.6
exploitability
3.5
remediation
6.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.