Qualcomm HLOS NULL Pointer Dereference Vulnerability Leading to Transient Denial-of-Service

Vulnerability

A vulnerability has been identified in Qualcomm's HLOS (High-Level Operating System) that allows for a NULL pointer dereference. This issue occurs when importing a PKCS#8-encoded RSA private key with a zero-sized modulus, leading to memory corruption. The vulnerability causes a transient denial-of-service condition.

Impact

Exploitation of this vulnerability causes a transient denial-of-service condition, where the system temporarily becomes unresponsive or unavailable.

Remediation

Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm July 2025 Security Bulletin.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
0.6
exploitability
4.9
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.