Description
Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling.
Published: 2026-04-06
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Use after free leading to memory corruption in Qualcomm camera driver
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from memory corruption when the camera driver accesses freed memory during concurrent fence deregistration and signal handling. This results in a use‑after‑free condition (CWE‑416). The primary impact is the potential alteration of memory contents, which could undermine the integrity of the device and, if exploited, could lead to denial of service or escalation of privileges within the firmware context.

Affected Systems

Qualcomm Snapdragon devices and associated firmware are affected. The issue spans a range of hardware, including Snapdragon AR1 Gen 1 platforms, Snapdragon XR series (SXR2230p, SXR2250p, SXR2330p, SXR2350p), various Wi‑Fi and Bluetooth modules (WCD9380, WCD9385, WCN7860, WCN7861), and modem components (FastConnect 6900/7800, Pandeiro, QLN1083BD/1086BD, QPA1083BD/1086BD, QXM1083/1086/1093/1094/1095/1096, SAR1165P, SAR2130P). Firmware versions are not specified in the advisory, so any firmware containing the vulnerable camera driver code is potentially impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The EPSS score is below 1%, suggesting a low probability of exploitation in the near term. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be device‑local, potentially triggered when the camera subsystem registers or deregisters fences concurrently with signal handling; an attacker would need to drive the camera driver into this race condition to exploit the use‑after‑free.

Generated by OpenCVE AI on April 8, 2026 at 23:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Qualcomm firmware update referenced in the April 2026 security bulletin.
  • Verify that the device firmware version matches the patched release listed in the bulletin.
  • If a firmware update is not yet available, restrict camera driver usage by disabling related services or applications.
  • Monitor device logs for signs of memory corruption or abnormal crashes related to camera activity.

Generated by OpenCVE AI on April 8, 2026 at 23:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm fastconnect 6900
Qualcomm fastconnect 6900 Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 7800 Firmware
Qualcomm pandeiro
Qualcomm pandeiro Firmware
Qualcomm qln1083bd
Qualcomm qln1083bd Firmware
Qualcomm qln1086bd
Qualcomm qln1086bd Firmware
Qualcomm qpa1083bd
Qualcomm qpa1083bd Firmware
Qualcomm qpa1086bd
Qualcomm qpa1086bd Firmware
Qualcomm qxm1083
Qualcomm qxm1083 Firmware
Qualcomm qxm1086
Qualcomm qxm1086 Firmware
Qualcomm qxm1093
Qualcomm qxm1093 Firmware
Qualcomm qxm1094
Qualcomm qxm1094 Firmware
Qualcomm qxm1095
Qualcomm qxm1095 Firmware
Qualcomm qxm1096
Qualcomm qxm1096 Firmware
Qualcomm sar1165p
Qualcomm sar1165p Firmware
Qualcomm sar2130p
Qualcomm sar2130p Firmware
Qualcomm snapdragon Ar1\+ Gen 1 Platform
Qualcomm snapdragon Ar1\+ Gen 1 Platform Firmware
Qualcomm snapdragon Ar1 Gen 1 Platform
Qualcomm snapdragon Ar1 Gen 1 Platform Firmware
Qualcomm sxr2230p
Qualcomm sxr2230p Firmware
Qualcomm sxr2250p
Qualcomm sxr2250p Firmware
Qualcomm sxr2330p
Qualcomm sxr2330p Firmware
Qualcomm sxr2350p
Qualcomm sxr2350p Firmware
Qualcomm wcd9380
Qualcomm wcd9380 Firmware
Qualcomm wcd9385
Qualcomm wcd9385 Firmware
Qualcomm wcn7860
Qualcomm wcn7860 Firmware
Qualcomm wcn7861
Qualcomm wcn7861 Firmware
Qualcomm wsa8830
Qualcomm wsa8830 Firmware
Qualcomm wsa8832
Qualcomm wsa8832 Firmware
Qualcomm wsa8835
Qualcomm wsa8835 Firmware
Qualcomm xrv7209
Qualcomm xrv7209 Firmware
Qualcomm xrv9209
Qualcomm xrv9209 Firmware
CPEs cpe:2.3:h:qualcomm:fastconnect_6900:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:pandeiro:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qln1083bd:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qln1086bd:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qpa1083bd:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qpa1086bd:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qxm1083:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qxm1086:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qxm1093:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qxm1094:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qxm1095:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qxm1096:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sar1165p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sar2130p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_ar1\+_gen_1_platform:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_ar1_gen_1_platform:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sxr2230p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sxr2250p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sxr2330p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sxr2350p:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9380:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9385:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn7860:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcn7861:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8830:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8832:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8835:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:xrv7209:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:xrv9209:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:pandeiro_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qln1083bd_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qln1086bd_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qpa1083bd_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qpa1086bd_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qxm1083_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qxm1086_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qxm1093_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qxm1094_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qxm1095_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qxm1096_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sar1165p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sar2130p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_ar1\+_gen_1_platform_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_ar1_gen_1_platform_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sxr2230p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sxr2250p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sxr2330p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sxr2350p_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn7860_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcn7861_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8830_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8832_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8835_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:xrv7209_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:xrv9209_firmware:-:*:*:*:*:*:*:*
Vendors & Products Qualcomm fastconnect 6900
Qualcomm fastconnect 6900 Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 7800 Firmware
Qualcomm pandeiro
Qualcomm pandeiro Firmware
Qualcomm qln1083bd
Qualcomm qln1083bd Firmware
Qualcomm qln1086bd
Qualcomm qln1086bd Firmware
Qualcomm qpa1083bd
Qualcomm qpa1083bd Firmware
Qualcomm qpa1086bd
Qualcomm qpa1086bd Firmware
Qualcomm qxm1083
Qualcomm qxm1083 Firmware
Qualcomm qxm1086
Qualcomm qxm1086 Firmware
Qualcomm qxm1093
Qualcomm qxm1093 Firmware
Qualcomm qxm1094
Qualcomm qxm1094 Firmware
Qualcomm qxm1095
Qualcomm qxm1095 Firmware
Qualcomm qxm1096
Qualcomm qxm1096 Firmware
Qualcomm sar1165p
Qualcomm sar1165p Firmware
Qualcomm sar2130p
Qualcomm sar2130p Firmware
Qualcomm snapdragon Ar1\+ Gen 1 Platform
Qualcomm snapdragon Ar1\+ Gen 1 Platform Firmware
Qualcomm snapdragon Ar1 Gen 1 Platform
Qualcomm snapdragon Ar1 Gen 1 Platform Firmware
Qualcomm sxr2230p
Qualcomm sxr2230p Firmware
Qualcomm sxr2250p
Qualcomm sxr2250p Firmware
Qualcomm sxr2330p
Qualcomm sxr2330p Firmware
Qualcomm sxr2350p
Qualcomm sxr2350p Firmware
Qualcomm wcd9380
Qualcomm wcd9380 Firmware
Qualcomm wcd9385
Qualcomm wcd9385 Firmware
Qualcomm wcn7860
Qualcomm wcn7860 Firmware
Qualcomm wcn7861
Qualcomm wcn7861 Firmware
Qualcomm wsa8830
Qualcomm wsa8830 Firmware
Qualcomm wsa8832
Qualcomm wsa8832 Firmware
Qualcomm wsa8835
Qualcomm wsa8835 Firmware
Qualcomm xrv7209
Qualcomm xrv7209 Firmware
Qualcomm xrv9209
Qualcomm xrv9209 Firmware

Tue, 07 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Mon, 06 Apr 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Apr 2026 16:45:00 +0000

Type Values Removed Values Added
Description Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling.
Title Use After Free in Camera Driver
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H'}


Subscriptions

Qualcomm Fastconnect 6900 Fastconnect 6900 Firmware Fastconnect 7800 Fastconnect 7800 Firmware Pandeiro Pandeiro Firmware Qln1083bd Qln1083bd Firmware Qln1086bd Qln1086bd Firmware Qpa1083bd Qpa1083bd Firmware Qpa1086bd Qpa1086bd Firmware Qxm1083 Qxm1083 Firmware Qxm1086 Qxm1086 Firmware Qxm1093 Qxm1093 Firmware Qxm1094 Qxm1094 Firmware Qxm1095 Qxm1095 Firmware Qxm1096 Qxm1096 Firmware Sar1165p Sar1165p Firmware Sar2130p Sar2130p Firmware Snapdragon Snapdragon Ar1\+ Gen 1 Platform Snapdragon Ar1\+ Gen 1 Platform Firmware Snapdragon Ar1 Gen 1 Platform Snapdragon Ar1 Gen 1 Platform Firmware Sxr2230p Sxr2230p Firmware Sxr2250p Sxr2250p Firmware Sxr2330p Sxr2330p Firmware Sxr2350p Sxr2350p Firmware Wcd9380 Wcd9380 Firmware Wcd9385 Wcd9385 Firmware Wcn7860 Wcn7860 Firmware Wcn7861 Wcn7861 Firmware Wsa8830 Wsa8830 Firmware Wsa8832 Wsa8832 Firmware Wsa8835 Wsa8835 Firmware Xrv7209 Xrv7209 Firmware Xrv9209 Xrv9209 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-04-06T16:32:18.294Z

Reserved: 2025-05-06T08:33:16.265Z

Link: CVE-2025-47374

cve-icon Vulnrichment

Updated: 2026-04-06T16:22:45.822Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-06T16:16:27.177

Modified: 2026-04-08T21:09:54.443

Link: CVE-2025-47374

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-09T08:29:02Z

Weaknesses