Qualcomm Snapdragon Buffer Over-read Vulnerability in Data HLOS - LNX Allowing Information Disclosure

Vulnerability

A buffer over-read vulnerability has been identified in the Data HLOS - LNX component of Qualcomm Snapdragon chipsets. This vulnerability allows for information disclosure by improperly handling RTP packet payloads received from the network. The issue arises from a buffer over-read, where data is read beyond the intended limit, potentially leading to unauthorized access to sensitive information.

Impact

Exploitation of this vulnerability can cause a transient denial-of-service condition by disrupting normal data processing, along with unauthorized information disclosure.

Remediation

Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm July 2025 Security Bulletin.

Added: Jul 8, 2025, 4:12 PM
Updated: Jul 8, 2025, 4:12 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
2.5
exploitability
7.0
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.