Qualcomm DSP Service Buffer Over-read Vulnerability Allowing Information Disclosure

Vulnerability

A buffer over-read vulnerability has been identified in the Digital Signal Processor (DSP) service of certain Qualcomm chipsets. This vulnerability arises from the IOCTL handler callbacks processing data without properly verifying the buffer size, leading to potential information disclosure.

Impact

Exploitation of this vulnerability could result in unauthorized information disclosure by allowing the reading of memory beyond the intended buffer limits.

Remediation

Qualcomm has released a patch for this vulnerability. Instructions for applying the patch can be found in the Qualcomm May 2026 Security Bulletin.

Added: May 4, 2026, 5:39 PM
Updated: May 4, 2026, 5:39 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
0.0
relevance
7.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.