Impact
This vulnerability arises when a component in Qualcomm Snapdragon systems copies input data larger than the expected allocation, causing an unintended memory corruption. The fault is essentially an untrusted pointer dereference that can overwrite adjacent memory, potentially enabling an attacker to execute arbitrary code or force a crash, compromising confidentiality, integrity, and availability.
Affected Systems
The affected systems are Qualcomm Snapdragon devices, specifically components associated with the Windows Compute environment as documented by Qualcomm. No specific product versions are listed in the CVE data, so all Snapdragon models that incorporate the vulnerable code may be at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS score of less than 1% suggests that far fewer attacks are expected today. The vulnerability is not listed in the CISA KEV catalog, which implies no widely used exploit has been observed. The likely attack vector is through a trusted input channel where an attacker can supply large payloads without proper bounds checking. An attacker with access to such a channel could trigger the memory corruption to achieve remote code execution or denial of service.
OpenCVE Enrichment