Qualcomm Products Use-After-Free Vulnerability in DSP Service

Vulnerability

A use-after-free vulnerability has been identified in various chipsets of Qualcomm products. This vulnerability can lead to memory corruption by allowing the simultaneous initiation of two IOCTL calls from different threads, potentially causing memory to be accessed after it has been freed.

Impact

Exploitation of this vulnerability can cause memory corruption, which may lead to arbitrary code execution or a denial-of-service condition.

Reproduction

To reproduce this vulnerability, send two IOCTL calls simultaneously from two different threads. This can be done by creating a process that initiates an IOCTL call and then quickly starting another process that does the same, before the first call has completed.

Remediation

Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm April 2025 Security Bulletin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
0.6
exploitability
3.4
remediation
7.7
relevance
0.0
threat
1.6
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.