Description
Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.
Published: 2026-05-04
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Snapdragon DSP Service contains an IOCTL handler that processes callback data without verifying the size of the supplied buffer, resulting in a buffer over‑read (CWE‑125, CWE‑126) that can expose sensitive memory contents. This flaw permits an attacker to read beyond the intended bounds of the IOCTL payload, potentially revealing confidential data.

Affected Systems

All Qualcomm Snapdragon processors that expose the DSP Service IOCTL interface are affected; no specific firmware or software version range was provided, so any device using this service is potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity. The EPSS score is < 1%, indicating a low but non-zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is operating either locally or remotely through crafted IOCTL calls to the DSP Service. At present no vendor patch or workaround has been released, so a precautionary patch when available should be prioritized.

Generated by OpenCVE AI on May 6, 2026 at 21:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an updated Qualcomm Snapdragon firmware or patch that implements proper buffer size validation for the DSP Service IOCTL handler.
  • Restrict access to the DSP Service IOCTL interface using role‑based access controls or device driver permissions, limiting how many processes can invoke it.
  • Monitor system logs for unusual IOCTL activity on the DSP Service and alert for potential exploitation attempts.

Generated by OpenCVE AI on May 6, 2026 at 21:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 06 May 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm cologne
Qualcomm cologne Firmware
Qualcomm fastconnect 6700
Qualcomm fastconnect 6700 Firmware
Qualcomm fastconnect 6900
Qualcomm fastconnect 6900 Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 7800 Firmware
Qualcomm iqx5121
Qualcomm iqx5121 Firmware
Qualcomm iqx7181
Qualcomm iqx7181 Firmware
Qualcomm qca0000
Qualcomm qca0000 Firmware
Qualcomm qcm5430
Qualcomm qcm5430 Firmware
Qualcomm qcm6490
Qualcomm qcm6490 Firmware
Qualcomm sc8380xp
Qualcomm sc8380xp Firmware
Qualcomm snapdragon 7c\+ Gen 3 Compute
Qualcomm snapdragon 7c\+ Gen 3 Compute Firmware
Qualcomm snapdragon 8cx Gen 3 Compute
Qualcomm snapdragon 8cx Gen 3 Compute Firmware
Qualcomm video Collaboration Vc3 Platform
Qualcomm video Collaboration Vc3 Platform Firmware
Qualcomm wcd9370
Qualcomm wcd9370 Firmware
Qualcomm wcd9375
Qualcomm wcd9375 Firmware
Qualcomm wcd9378c
Qualcomm wcd9378c Firmware
Qualcomm wcd9380
Qualcomm wcd9380 Firmware
Qualcomm wcd9385
Qualcomm wcd9385 Firmware
Qualcomm wsa8830
Qualcomm wsa8830 Firmware
Qualcomm wsa8835
Qualcomm wsa8835 Firmware
Qualcomm wsa8840
Qualcomm wsa8840 Firmware
Qualcomm wsa8845
Qualcomm wsa8845 Firmware
Qualcomm wsa8845h
Qualcomm wsa8845h Firmware
Qualcomm x2000077
Qualcomm x2000077 Firmware
Qualcomm x2000086
Qualcomm x2000086 Firmware
Qualcomm x2000090
Qualcomm x2000090 Firmware
Qualcomm x2000092
Qualcomm x2000092 Firmware
Qualcomm x2000094
Qualcomm x2000094 Firmware
Qualcomm xg101002
Qualcomm xg101002 Firmware
Qualcomm xg101032
Qualcomm xg101032 Firmware
Qualcomm xg101039
Qualcomm xg101039 Firmware
Weaknesses CWE-125
CPEs cpe:2.3:h:qualcomm:cologne:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_6700:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_6900:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:iqx5121:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:iqx7181:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca0000:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcm5430:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcm6490:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sc8380xp:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_7c\+_gen_3_compute:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_8cx_gen_3_compute:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:video_collaboration_vc3_platform:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9370:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9375:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9378c:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9380:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9385:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8830:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8835:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8840:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845h:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:x2000077:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:x2000086:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:x2000090:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:x2000092:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:x2000094:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:xg101002:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:xg101032:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:xg101039:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:cologne_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_6700_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:iqx5121_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:iqx7181_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qca0000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qcm5430_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qcm6490_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sc8380xp_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_7c\+_gen_3_compute_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_8cx_gen_3_compute_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:video_collaboration_vc3_platform_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9370_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9375_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9378c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8830_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8835_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:x2000077_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:x2000086_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:x2000090_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:x2000092_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:x2000094_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:xg101002_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:xg101032_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:xg101039_firmware:-:*:*:*:*:*:*:*
Vendors & Products Qualcomm cologne
Qualcomm cologne Firmware
Qualcomm fastconnect 6700
Qualcomm fastconnect 6700 Firmware
Qualcomm fastconnect 6900
Qualcomm fastconnect 6900 Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 7800 Firmware
Qualcomm iqx5121
Qualcomm iqx5121 Firmware
Qualcomm iqx7181
Qualcomm iqx7181 Firmware
Qualcomm qca0000
Qualcomm qca0000 Firmware
Qualcomm qcm5430
Qualcomm qcm5430 Firmware
Qualcomm qcm6490
Qualcomm qcm6490 Firmware
Qualcomm sc8380xp
Qualcomm sc8380xp Firmware
Qualcomm snapdragon 7c\+ Gen 3 Compute
Qualcomm snapdragon 7c\+ Gen 3 Compute Firmware
Qualcomm snapdragon 8cx Gen 3 Compute
Qualcomm snapdragon 8cx Gen 3 Compute Firmware
Qualcomm video Collaboration Vc3 Platform
Qualcomm video Collaboration Vc3 Platform Firmware
Qualcomm wcd9370
Qualcomm wcd9370 Firmware
Qualcomm wcd9375
Qualcomm wcd9375 Firmware
Qualcomm wcd9378c
Qualcomm wcd9378c Firmware
Qualcomm wcd9380
Qualcomm wcd9380 Firmware
Qualcomm wcd9385
Qualcomm wcd9385 Firmware
Qualcomm wsa8830
Qualcomm wsa8830 Firmware
Qualcomm wsa8835
Qualcomm wsa8835 Firmware
Qualcomm wsa8840
Qualcomm wsa8840 Firmware
Qualcomm wsa8845
Qualcomm wsa8845 Firmware
Qualcomm wsa8845h
Qualcomm wsa8845h Firmware
Qualcomm x2000077
Qualcomm x2000077 Firmware
Qualcomm x2000086
Qualcomm x2000086 Firmware
Qualcomm x2000090
Qualcomm x2000090 Firmware
Qualcomm x2000092
Qualcomm x2000092 Firmware
Qualcomm x2000094
Qualcomm x2000094 Firmware
Qualcomm xg101002
Qualcomm xg101002 Firmware
Qualcomm xg101032
Qualcomm xg101032 Firmware
Qualcomm xg101039
Qualcomm xg101039 Firmware

Mon, 04 May 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Mon, 04 May 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 04 May 2026 17:15:00 +0000

Type Values Removed Values Added
Description Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.
Title Buffer Over-read in DSP Service
Weaknesses CWE-126
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


Subscriptions

Qualcomm Cologne Cologne Firmware Fastconnect 6700 Fastconnect 6700 Firmware Fastconnect 6900 Fastconnect 6900 Firmware Fastconnect 7800 Fastconnect 7800 Firmware Iqx5121 Iqx5121 Firmware Iqx7181 Iqx7181 Firmware Qca0000 Qca0000 Firmware Qcm5430 Qcm5430 Firmware Qcm6490 Qcm6490 Firmware Sc8380xp Sc8380xp Firmware Snapdragon Snapdragon 7c\+ Gen 3 Compute Snapdragon 7c\+ Gen 3 Compute Firmware Snapdragon 8cx Gen 3 Compute Snapdragon 8cx Gen 3 Compute Firmware Video Collaboration Vc3 Platform Video Collaboration Vc3 Platform Firmware Wcd9370 Wcd9370 Firmware Wcd9375 Wcd9375 Firmware Wcd9378c Wcd9378c Firmware Wcd9380 Wcd9380 Firmware Wcd9385 Wcd9385 Firmware Wsa8830 Wsa8830 Firmware Wsa8835 Wsa8835 Firmware Wsa8840 Wsa8840 Firmware Wsa8845 Wsa8845 Firmware Wsa8845h Wsa8845h Firmware X2000077 X2000077 Firmware X2000086 X2000086 Firmware X2000090 X2000090 Firmware X2000092 X2000092 Firmware X2000094 X2000094 Firmware Xg101002 Xg101002 Firmware Xg101032 Xg101032 Firmware Xg101039 Xg101039 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-05-04T17:50:51.545Z

Reserved: 2025-05-06T08:33:16.277Z

Link: CVE-2025-47406

cve-icon Vulnrichment

Updated: 2026-05-04T17:46:29.428Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-04T17:16:20.957

Modified: 2026-05-06T18:02:52.680

Link: CVE-2025-47406

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-06T21:45:13Z

Weaknesses