Buffer over-read in Qualcomm products - CVE-2025-27064

 

Buffer over-read in Qualcomm products - CVE-2025-27064

Published: December 2, 2025


Vulnerability identifier: #VU119029
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-27064
CWE-ID: CWE-126
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to read and manipulate data.

The vulnerability exists due to improper input validation in Core Services. A local application can read and manipulate data.


Affected software

QCN6422
SA4150P
QXM8083
QCN9274
QCN9160
QCN9074
QCN9024
QCN9012
QCN9000
QCN6432
SA4155P
QCN6412
QCN6402
QCN5224
QCN5124
QCF8001
QCF8000
QCA9367
QCA8386
WSA8835
WSA8830
WCN3980
WCN3680B
WCN3660B
WCD9380
SXR2250P
Snapdragon Auto 5G Modem-RF Gen 2
Snapdragon 8 Gen 1 Mobile Platform
QCA8385
SA8650P
SA8530P
SA8255P
SA8195P
SA8155P
SA7255P
IPQ9008
QCA6564A
QCA0000
QAM8650P
QAM8255P
MDM9628
IPQ9574
IPQ9570
IPQ9554
IPQ9048
QCA6564AU
IPQ5424
IPQ5332
IPQ5312
IPQ5302
IPQ5300
Immersive Home 326 Platform
Immersive Home 3210 Platform
FastConnect 7800
QCA8080
QCA8384
QCA8112
QCA8111
QCA8102
QCA8101
QCA8085
QCA8084
QCA8082
QCA8081
FastConnect 6900
QCA8075
QCA6698AQ
QCA6688AQ
QCA6678AQ
QCA6595AU
QCA6584AU
QCA6574A
QCA9377
SA9000P
SA8540P
SA6155P
QCA6574AU

How to mitigate CVE-2025-27064

Install security update from vendor's website.


External References

Related Security Bulletins