Description
Memory corruption when processing camera sensor input/output control codes with invalid output buffers.
Published: 2026-05-04
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates in the camera subsystem when the driver processes sensor I/O control codes with improperly sized output buffers. This flaw allows an attacker to cause a memory corruption that may result in a crash or, in some conditions, arbitrary code execution. The weakness is a classic untrusted pointer dereference, corresponding to CWE‑119: Improper Restriction of Operations within the Bounds of a Memory Buffer, offering potential for confidentiality, integrity, and availability violations.

Affected Systems

Qualcomm Snapdragon devices are affected; specific firmware or driver versions are not listed in the public data, so any device utilizing the camera drivers outlined by Qualcomm may be vulnerable.

Risk and Exploitability

With a CVSS score of 7.8, the vulnerability is considered high severity. The EPSS score is <1%, indicating a low exploitation probability, and the issue is not listed in the CISA KEV catalog. The likely attack vector involves crafting malicious camera sensor input or output control commands that a compromised or malicious application could deliver, especially on systems where the camera driver runs with elevated privileges. If successfully exploited, the attacker could gain arbitrary code execution on the device or force a denial of service by crashing the camera subsystem.

Generated by OpenCVE AI on May 6, 2026 at 21:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch or firmware update that corrects the camera driver buffer handling
  • Disable or remove the camera module from devices that do not require camera functionality
  • Restrict camera driver access to only trusted applications by enforcing strict permission policies
  • Monitor system logs for unexpected camera driver crashes or abnormal memory accesses as an early detection mechanism

Generated by OpenCVE AI on May 6, 2026 at 21:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 06 May 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm fastconnect 6900
Qualcomm fastconnect 6900 Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 7800 Firmware
Qualcomm iqx5121
Qualcomm iqx5121 Firmware
Qualcomm iqx7181
Qualcomm iqx7181 Firmware
Qualcomm qca0000
Qualcomm qca0000 Firmware
Qualcomm sc8380xp
Qualcomm sc8380xp Firmware
Qualcomm sd865 5g
Qualcomm sd865 5g Firmware
Qualcomm snapdragon Xr2\+ Gen 1
Qualcomm snapdragon Xr2\+ Gen 1 Firmware
Qualcomm snapdragon Xr2 5g
Qualcomm snapdragon Xr2 5g Firmware
Qualcomm wcd9380
Qualcomm wcd9380 Firmware
Qualcomm wcd9385
Qualcomm wcd9385 Firmware
Qualcomm wsa8810
Qualcomm wsa8810 Firmware
Qualcomm wsa8815
Qualcomm wsa8815 Firmware
Qualcomm wsa8840
Qualcomm wsa8840 Firmware
Qualcomm wsa8845
Qualcomm wsa8845 Firmware
Qualcomm wsa8845h
Qualcomm wsa8845h Firmware
Weaknesses CWE-119
CPEs cpe:2.3:h:qualcomm:fastconnect_6900:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:iqx5121:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:iqx7181:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca0000:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sc8380xp:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd865_5g:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_xr2\+_gen_1:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_xr2_5g:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9380:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9385:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8810:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8815:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8840:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845h:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:iqx5121_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:iqx7181_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qca0000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sc8380xp_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sd865_5g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_xr2\+_gen_1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_xr2_5g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8810_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8815_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*
Vendors & Products Qualcomm fastconnect 6900
Qualcomm fastconnect 6900 Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 7800 Firmware
Qualcomm iqx5121
Qualcomm iqx5121 Firmware
Qualcomm iqx7181
Qualcomm iqx7181 Firmware
Qualcomm qca0000
Qualcomm qca0000 Firmware
Qualcomm sc8380xp
Qualcomm sc8380xp Firmware
Qualcomm sd865 5g
Qualcomm sd865 5g Firmware
Qualcomm snapdragon Xr2\+ Gen 1
Qualcomm snapdragon Xr2\+ Gen 1 Firmware
Qualcomm snapdragon Xr2 5g
Qualcomm snapdragon Xr2 5g Firmware
Qualcomm wcd9380
Qualcomm wcd9380 Firmware
Qualcomm wcd9385
Qualcomm wcd9385 Firmware
Qualcomm wsa8810
Qualcomm wsa8810 Firmware
Qualcomm wsa8815
Qualcomm wsa8815 Firmware
Qualcomm wsa8840
Qualcomm wsa8840 Firmware
Qualcomm wsa8845
Qualcomm wsa8845 Firmware
Qualcomm wsa8845h
Qualcomm wsa8845h Firmware

Mon, 04 May 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Mon, 04 May 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 04 May 2026 17:15:00 +0000

Type Values Removed Values Added
Description Memory corruption when processing camera sensor input/output control codes with invalid output buffers.
Title Untrusted Pointer Dereference in Camera
Weaknesses CWE-822
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Qualcomm Fastconnect 6900 Fastconnect 6900 Firmware Fastconnect 7800 Fastconnect 7800 Firmware Iqx5121 Iqx5121 Firmware Iqx7181 Iqx7181 Firmware Qca0000 Qca0000 Firmware Sc8380xp Sc8380xp Firmware Sd865 5g Sd865 5g Firmware Snapdragon Snapdragon Xr2\+ Gen 1 Snapdragon Xr2\+ Gen 1 Firmware Snapdragon Xr2 5g Snapdragon Xr2 5g Firmware Wcd9380 Wcd9380 Firmware Wcd9385 Wcd9385 Firmware Wsa8810 Wsa8810 Firmware Wsa8815 Wsa8815 Firmware Wsa8840 Wsa8840 Firmware Wsa8845 Wsa8845 Firmware Wsa8845h Wsa8845h Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-05-05T03:56:29.891Z

Reserved: 2025-05-06T08:33:16.277Z

Link: CVE-2025-47405

cve-icon Vulnrichment

Updated: 2026-05-04T17:21:30.264Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-04T17:16:20.827

Modified: 2026-05-06T18:03:08.820

Link: CVE-2025-47405

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-06T21:45:13Z

Weaknesses