Description
Memory Corruption when sending random number generator command with insufficient output buffer size.
Published: 2026-06-01
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer size validation bug triggers an out‑of‑bounds write when a random number generator command is sent with an insufficient output buffer. The write can corrupt adjacent memory, and based on the description it is inferred that if an attacker can influence the command payload, they could exploit the corruption to raise privileges or execute arbitrary code. The weakness corresponds to CWE‑787 and represents a moderate severity scenario, as reflected by the CVSS score of 6.7.

Affected Systems

Qualcomm Snapdragon processors running on Windows compute platforms are impacted. Specific firmware or driver versions are not listed in the advisory; any installation of Qualcomm Snapdragon components on Windows systems is potentially vulnerable until a patch is applied.

Risk and Exploitability

The vulnerability is listed with a CVSS score of 6.7, but the EPSS score is not reported, making exploitation likelihood unclear. It is not currently listed in the CISA KEV catalog, suggesting the vulnerability may not yet be widely exploited in the wild. It is inferred that attackers would need to be able to send a crafted RNG command to a local process with sufficient privileges, implying a local or controlled scenario rather than a remote attack vector.

Generated by OpenCVE AI on June 2, 2026 at 00:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Qualcomm Snapdragon firmware or driver updates for Windows compute platforms, which fix the RNG output buffer validation flaw.
  • Apply Windows Least‑Privilege policies to restrict access to the RNG command interface, ensuring that only trusted system components can invoke random number generator operations.
  • For systems where the update is not yet available, disable or restrict the RNG utility or command execution for untrusted processes until the vendor issue is resolved.

Generated by OpenCVE AI on June 2, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 02 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm cologne
Qualcomm cologne Firmware
Qualcomm fastconnect 6900
Qualcomm fastconnect 6900 Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 7800 Firmware
Qualcomm iqx5121
Qualcomm iqx5121 Firmware
Qualcomm iqx7181
Qualcomm iqx7181 Firmware
Qualcomm qca0000
Qualcomm qca0000 Firmware
Qualcomm sc8380xp
Qualcomm sc8380xp Firmware
Qualcomm wcd9378c
Qualcomm wcd9378c Firmware
Qualcomm wcd9380
Qualcomm wcd9380 Firmware
Qualcomm wcd9385
Qualcomm wcd9385 Firmware
Qualcomm wsa8840
Qualcomm wsa8840 Firmware
Qualcomm wsa8845
Qualcomm wsa8845 Firmware
Qualcomm wsa8845h
Qualcomm wsa8845h Firmware
Qualcomm x2000077
Qualcomm x2000077 Firmware
Qualcomm x2000086
Qualcomm x2000086 Firmware
Qualcomm x2000090
Qualcomm x2000090 Firmware
Qualcomm x2000092
Qualcomm x2000092 Firmware
Qualcomm x2000094
Qualcomm x2000094 Firmware
Qualcomm xg101002
Qualcomm xg101002 Firmware
Qualcomm xg101032
Qualcomm xg101032 Firmware
Qualcomm xg101039
Qualcomm xg101039 Firmware
CPEs cpe:2.3:h:qualcomm:cologne:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_6900:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:iqx5121:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:iqx7181:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca0000:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sc8380xp:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9378c:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9380:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9385:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8840:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845h:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:x2000077:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:x2000086:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:x2000090:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:x2000092:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:x2000094:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:xg101002:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:xg101032:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:xg101039:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:cologne_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:iqx5121_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:iqx7181_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:qca0000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:sc8380xp_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9378c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:x2000077_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:x2000086_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:x2000090_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:x2000092_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:x2000094_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:xg101002_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:xg101032_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:xg101039_firmware:-:*:*:*:*:*:*:*
Vendors & Products Qualcomm cologne
Qualcomm cologne Firmware
Qualcomm fastconnect 6900
Qualcomm fastconnect 6900 Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 7800 Firmware
Qualcomm iqx5121
Qualcomm iqx5121 Firmware
Qualcomm iqx7181
Qualcomm iqx7181 Firmware
Qualcomm qca0000
Qualcomm qca0000 Firmware
Qualcomm sc8380xp
Qualcomm sc8380xp Firmware
Qualcomm wcd9378c
Qualcomm wcd9378c Firmware
Qualcomm wcd9380
Qualcomm wcd9380 Firmware
Qualcomm wcd9385
Qualcomm wcd9385 Firmware
Qualcomm wsa8840
Qualcomm wsa8840 Firmware
Qualcomm wsa8845
Qualcomm wsa8845 Firmware
Qualcomm wsa8845h
Qualcomm wsa8845h Firmware
Qualcomm x2000077
Qualcomm x2000077 Firmware
Qualcomm x2000086
Qualcomm x2000086 Firmware
Qualcomm x2000090
Qualcomm x2000090 Firmware
Qualcomm x2000092
Qualcomm x2000092 Firmware
Qualcomm x2000094
Qualcomm x2000094 Firmware
Qualcomm xg101002
Qualcomm xg101002 Firmware
Qualcomm xg101032
Qualcomm xg101032 Firmware
Qualcomm xg101039
Qualcomm xg101039 Firmware

Tue, 02 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Tue, 02 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 01 Jun 2026 22:30:00 +0000

Type Values Removed Values Added
Description Memory Corruption when sending random number generator command with insufficient output buffer size.
Title Out-of-bounds Write in Windows Compute
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Qualcomm Cologne Cologne Firmware Fastconnect 6900 Fastconnect 6900 Firmware Fastconnect 7800 Fastconnect 7800 Firmware Iqx5121 Iqx5121 Firmware Iqx7181 Iqx7181 Firmware Qca0000 Qca0000 Firmware Sc8380xp Sc8380xp Firmware Snapdragon Wcd9378c Wcd9378c Firmware Wcd9380 Wcd9380 Firmware Wcd9385 Wcd9385 Firmware Wsa8840 Wsa8840 Firmware Wsa8845 Wsa8845 Firmware Wsa8845h Wsa8845h Firmware X2000077 X2000077 Firmware X2000086 X2000086 Firmware X2000090 X2000090 Firmware X2000092 X2000092 Firmware X2000094 X2000094 Firmware Xg101002 Xg101002 Firmware Xg101032 Xg101032 Firmware Xg101039 Xg101039 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-06-02T13:04:38.484Z

Reserved: 2025-09-18T03:19:23.202Z

Link: CVE-2025-59614

cve-icon Vulnrichment

Updated: 2026-06-02T13:04:35.415Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-01T23:16:16.863

Modified: 2026-06-02T15:26:34.057

Link: CVE-2025-59614

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T14:45:10Z

Weaknesses