Qualcomm Products Buffer Over-Read Vulnerability in Data Network Stack & Connectivity

Vulnerability

A buffer over-read vulnerability has been identified in various chipsets by Qualcomm. This vulnerability allows for information disclosure while decoding RTP packet headers received by the user equipment (UE) from the network, specifically when the padding bit is set. The issue arises in the data network stack and connectivity area, affecting several chipsets across different Qualcomm platforms.

Impact

Exploitation of this vulnerability leads to a buffer over-read, causing a global buffer overflow and allowing for information disclosure.

Remediation

Qualcomm has notified device manufacturers about this vulnerability and is actively sharing patches. Instructions for applying the patch can be found in the Qualcomm September 2025 Security Bulletin.

Added: Sep 24, 2025, 5:38 PM
Updated: Sep 24, 2025, 8:51 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
5.4
remediation
8.3
relevance
0.6
threat
0.0
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.