Qualcomm DSP Service Memory Corruption Vulnerability Allowing Concurrent Memory Mapping and Unmapping

Vulnerability

A high-impact memory corruption vulnerability has been identified in Qualcomm's DSP service. This issue arises from improper handling of concurrent memory mapping and unmapping requests from user-space applications, leading to a use-after-free condition. The vulnerability is present in various chipsets, including those used in mobile platforms, automotive applications, and video collaboration devices.

Impact

Exploitation of this vulnerability causes memory corruption, which can lead to arbitrary code execution or the introduction of a denial-of-service condition.

Remediation

Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm December 2025 Security Bulletin.

Added: Dec 18, 2025, 6:35 AM
Updated: Dec 18, 2025, 6:35 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.6
exploitability
2.9
remediation
7.7
relevance
1.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.