#VU114653 Buffer overflow in Qualcomm products - CVE-2025-21476

 

#VU114653 Buffer overflow in Qualcomm products - CVE-2025-21476

Published: September 1, 2025


Vulnerability identifier: #VU114653
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-21476
CWE-ID: CWE-120
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
QCM5430
QCM6490
QCM8550
QCS5430
QCS615
QCS6490
QCS8550
QCS9100
SG8275
SG8275P
SM6650
SM7635
SM7675
SM7675P
SM8550
SM8550P
SM8635
SM8635P
SM8650
SM8650P
SM8650Q
SM8750
SM8750P
SXR2330P
QCA6391
QCA6698AQ
QCN9011
QCN9012
QCN9274
WCN3910
WCN3950
WCN6650
WCN6750
WCN6755
WCN6855
WCN6856
WCN7850
WCN7851
WCN7860
WCN7861
WCN7880
WCN7881
Software vendor:
Qualcomm

Description

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in Computer Vision. A local application can execute arbitrary code.


Remediation

Install security update from vendor's website.

External links