Description
Memory corruption when another driver calls an IOCTL with invalid input/output buffer.
Published: 2026-05-04
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Memory corruption occurs when an external driver invokes an IOCTL operation with invalid input or output buffers. The untrusted pointer dereference can overwrite kernel memory, potentially allowing an attacker to execute arbitrary code or gain elevated privileges. The weakness corresponds to CWE-119 and CWE-822. The description indicates direct memory corruption rather than an informational disclosure, so the primary security impact is modification of system state by a privileged entity.

Affected Systems

The vulnerability affects Qualcomm, Inc. Snapdragon firmware, specifically the power optimization component. No version details are provided; all Snapdragon devices that incorporate the vulnerable power optimization firmware are potentially impacted.

Risk and Exploitability

The CVSS score of 7.8 classifies this issue as a high severity vulnerability. The EPSS score is < 1%, indicating a low but non‑zero exploitation probability, so the attacker would need a local driver‑level privilege to trigger the vulnerability. The vulnerability is not yet listed in the CISA KEV catalog, indicating no confirmed active exploitation at this time. Based on the description, the attack vector is inferred to be a local driver‑level request; an attacker could trigger the exploit by loading a malicious driver that performs the offending IOCTL or by compromising a legitimate driver that is allowed to call it. If the attacker can run code with driver privileges, the corruption could lead to remote code execution or privilege escalation across the kernel space.

Generated by OpenCVE AI on May 6, 2026 at 21:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Qualcomm firmware update that fixes the power optimization driver pointer dereference.
  • Disable or unload the Power Optimization firmware module while the patch is pending to eliminate the exploitable entry point.
  • Configure the device to restrict IOCTL access to trusted drivers, such as by enabling driver authentication or ACL mechanisms for the power optimization IOCTL interface.

Generated by OpenCVE AI on May 6, 2026 at 21:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 06 May 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm fastconnect 6200
Qualcomm fastconnect 6200 Firmware
Qualcomm fastconnect 6900
Qualcomm fastconnect 6900 Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 7800 Firmware
Qualcomm iqx5121
Qualcomm iqx5121 Firmware
Qualcomm iqx7181
Qualcomm iqx7181 Firmware
Qualcomm qca0000
Qualcomm qca0000 Firmware
Qualcomm sc8380xp
Qualcomm sc8380xp Firmware
Qualcomm sd865 5g
Qualcomm sd865 5g Firmware
Qualcomm sm6250
Qualcomm sm6250 Firmware
Qualcomm snapdragon 7c Compute
Qualcomm snapdragon 7c Compute Firmware
Qualcomm snapdragon 7c Gen 2 Compute
Qualcomm snapdragon 7c Gen 2 Compute Firmware
Qualcomm snapdragon Xr2\+ Gen 1
Qualcomm snapdragon Xr2\+ Gen 1 Firmware
Qualcomm snapdragon Xr2 5g
Qualcomm snapdragon Xr2 5g Firmware
Qualcomm wcd9380
Qualcomm wcd9380 Firmware
Qualcomm wcd9385
Qualcomm wcd9385 Firmware
Qualcomm wsa8810
Qualcomm wsa8810 Firmware
Qualcomm wsa8815
Qualcomm wsa8815 Firmware
Qualcomm wsa8840
Qualcomm wsa8840 Firmware
Qualcomm wsa8845
Qualcomm wsa8845 Firmware
Qualcomm wsa8845h
Qualcomm wsa8845h Firmware
Weaknesses CWE-119
CPEs cpe:2.3:h:qualcomm:fastconnect_6200:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_6900:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:iqx5121:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:iqx7181:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca0000:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sc8380xp:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd865_5g:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sm6250:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_7c_compute:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_7c_gen_2_compute:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_xr2\+_gen_1:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_xr2_5g:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9380:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9385:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8810:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8815:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8840:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845h:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_6200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:iqx5121_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:iqx7181_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qca0000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sc8380xp_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sd865_5g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sm6250_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_7c_compute_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_7c_gen_2_compute_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_xr2\+_gen_1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_xr2_5g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8810_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8815_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*
Vendors & Products Qualcomm fastconnect 6200
Qualcomm fastconnect 6200 Firmware
Qualcomm fastconnect 6900
Qualcomm fastconnect 6900 Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 7800 Firmware
Qualcomm iqx5121
Qualcomm iqx5121 Firmware
Qualcomm iqx7181
Qualcomm iqx7181 Firmware
Qualcomm qca0000
Qualcomm qca0000 Firmware
Qualcomm sc8380xp
Qualcomm sc8380xp Firmware
Qualcomm sd865 5g
Qualcomm sd865 5g Firmware
Qualcomm sm6250
Qualcomm sm6250 Firmware
Qualcomm snapdragon 7c Compute
Qualcomm snapdragon 7c Compute Firmware
Qualcomm snapdragon 7c Gen 2 Compute
Qualcomm snapdragon 7c Gen 2 Compute Firmware
Qualcomm snapdragon Xr2\+ Gen 1
Qualcomm snapdragon Xr2\+ Gen 1 Firmware
Qualcomm snapdragon Xr2 5g
Qualcomm snapdragon Xr2 5g Firmware
Qualcomm wcd9380
Qualcomm wcd9380 Firmware
Qualcomm wcd9385
Qualcomm wcd9385 Firmware
Qualcomm wsa8810
Qualcomm wsa8810 Firmware
Qualcomm wsa8815
Qualcomm wsa8815 Firmware
Qualcomm wsa8840
Qualcomm wsa8840 Firmware
Qualcomm wsa8845
Qualcomm wsa8845 Firmware
Qualcomm wsa8845h
Qualcomm wsa8845h Firmware

Mon, 04 May 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Mon, 04 May 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 04 May 2026 17:15:00 +0000

Type Values Removed Values Added
Description Memory corruption when another driver calls an IOCTL with invalid input/output buffer.
Title Untrusted Pointer Dereference in Power Optimization Firmware
Weaknesses CWE-822
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Qualcomm Fastconnect 6200 Fastconnect 6200 Firmware Fastconnect 6900 Fastconnect 6900 Firmware Fastconnect 7800 Fastconnect 7800 Firmware Iqx5121 Iqx5121 Firmware Iqx7181 Iqx7181 Firmware Qca0000 Qca0000 Firmware Sc8380xp Sc8380xp Firmware Sd865 5g Sd865 5g Firmware Sm6250 Sm6250 Firmware Snapdragon Snapdragon 7c Compute Snapdragon 7c Compute Firmware Snapdragon 7c Gen 2 Compute Snapdragon 7c Gen 2 Compute Firmware Snapdragon Xr2\+ Gen 1 Snapdragon Xr2\+ Gen 1 Firmware Snapdragon Xr2 5g Snapdragon Xr2 5g Firmware Wcd9380 Wcd9380 Firmware Wcd9385 Wcd9385 Firmware Wsa8810 Wsa8810 Firmware Wsa8815 Wsa8815 Firmware Wsa8840 Wsa8840 Firmware Wsa8845 Wsa8845 Firmware Wsa8845h Wsa8845h Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-05-05T03:56:27.690Z

Reserved: 2025-05-06T08:33:16.278Z

Link: CVE-2025-47408

cve-icon Vulnrichment

Updated: 2026-05-04T17:53:42.394Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-04T17:16:21.257

Modified: 2026-05-06T18:03:00.557

Link: CVE-2025-47408

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-06T21:45:13Z

Weaknesses