Buffer overflow in Qualcomm products - CVE-2025-47321

 

Buffer overflow in Qualcomm products - CVE-2025-47321

Published: December 2, 2025


Vulnerability identifier: #VU119036
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-47321
CWE-ID: CWE-120
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in Core Services. A local application can execute arbitrary code.


Affected software

Snapdragon 768G 5G Mobile Platform (SM7250-AC)
SXR1230P
SW5100P
SW5100
SSG2125P
SSG2115P
SRV1M
SRV1H
Snapdragon X65 5G Modem-RF System
Snapdragon X35 5G Modem-RF System
Snapdragon X32 5G Modem-RF System
Snapdragon W5+ Gen 1 Wearable Platform
Snapdragon AR2 Gen 1 Platform
Snapdragon AR1 Gen 1 Platform "Luna1"
Snapdragon AR1 Gen 1 Platform
SXR2230P
Snapdragon 765G 5G Mobile Platform (SM7250-AB)
Snapdragon 765 5G Mobile Platform (SM7250-AA)
Snapdragon 685 4G Mobile Platform (SM6225-AD)
Snapdragon 680 4G Mobile Platform
Snapdragon 6 Gen 1 Mobile Platform
Snapdragon 4 Gen 2 Mobile Platform
Smart Audio 400 Platform
SM8750P
SM8750
SM8735
SM7635P
SM7635
SM7435
WCN6740
WSA8845H
WSA8845
WSA8840
WSA8835
WSA8830
WSA8815
WSA8810
WCN7881
WCN7880
WCN7861
WCN7860
WCN7750
WCN6755
SM7250P
WCN6650
WCN3988
WCN3980
WCN3950
WCD9395
WCD9385
WCD9380
WCD9378
WCD9375
WCD9370
WCD9340
WCD9335
SXR2250P
QCN9011
QCN6024
QCM8550
QCM6490
QCM6125
QCM5430
QCA8337
QCA8081
QCA6696
QCA6595AU
QCA6574A
QCA6574
QCA6391
QCN9012
QCA2066
QAMSRV1M
QAMSRV1H
QAM8775P
QAM8650P
QAM8255P
FastConnect 7800
FastConnect 6900
FastConnect 6700
FastConnect 6200
CSRA6640
CSRA6620
AR8035
SA7255P
SM6650P
SM6650
SM6475
SDX61
SA8775P
SA8770P
SA8650P
SA8255P
SA8195P
SA8155P
SA7775P
AR8031
SA4155P
SA4150P
Robotics RB2 Platform
Qualcommr Video Collaboration VC3 Platform
Qualcommr Video Collaboration VC1 Platform
QMP1000
QEP8111
QCS8550
QCS6490
QCS6125
QCS5430
QCN9024
WSA8832
QCA6174A
QCA6574AU
SA9000P
SA8620P
SA6155P

How to mitigate CVE-2025-47321

Install security update from vendor's website.


External References

Related Security Bulletins