Qualcomm Products Buffer Copy Without Size Check Vulnerability in Core Services

Vulnerability

A memory corruption vulnerability has been identified in various chipsets of Qualcomm products, including those in the Snapdragon series, due to improper handling of data packets in the diagnostics interface. This issue arises from a classic buffer overflow, where the vulnerability can be exploited by sending specially crafted packets from Unix clients, leading to memory corruption.

Impact

Exploitation of this vulnerability causes memory corruption, which can potentially be leveraged to execute arbitrary code or cause a denial-of-service condition by crashing the affected process or system.

Remediation

Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm July 2025 Security Bulletin.

Added: Jul 8, 2025, 2:00 PM
Updated: Jul 8, 2025, 2:00 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
1.3
exploitability
3.5
remediation
6.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.