Qualcomm Automotive Vehicle Networks Buffer Copy Without Checking Size of Input Vulnerability

Vulnerability

A buffer overflow vulnerability has been identified in Qualcomm's implementation of the Automotive Ethernet Audio Video Bridging (eAVB) protocol. This vulnerability arises from memory corruption while processing message content, which can be exploited by sending specially crafted packets that violate the protocol's specifications. The issue affects several chipsets used in automotive applications, potentially leading to arbitrary code execution or other malicious actions.

Impact

Exploitation of this vulnerability causes memory corruption, which can be leveraged to execute arbitrary code or create a denial-of-service condition by causing a system crash.

Remediation

Qualcomm has developed patches for this vulnerability, which are available through the Qualcomm Update Catalog. Instructions for applying the patch can be obtained from the device manufacturer.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
5.0
exploitability
3.5
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.