Qualcomm Camera Driver Improper Access Control Vulnerability Allowing Memory Corruption

Vulnerability

A vulnerability has been identified in the Qualcomm camera driver, specifically in the image encoding process. When the input buffer length is zero in an IOCTL call, it can lead to memory corruption. This issue arises from improper validation of input, allowing for potential exploitation.

Impact

Exploitation of this vulnerability causes memory corruption, which can lead to undefined behavior such as application crashes or arbitrary code execution.

Remediation

Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm May 2025 Security Bulletin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
3.3
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.