Impact
This vulnerability is a use‑after processes I/O control calls to map and later unmap persistent memory buffers without synchronization, causing the kernel to reference memory that has already been freed, potentially leading to unpredictable memory corruption. While it is not explicitly stated whether this can be leveraged for arbitrary code execution, such memory corruption would typically allow an attacker to alter kernel state in a way that could compromise system integrity or stability.
Affected Systems
Qualcomm’s Snapdragon platform is affected. The data does not list specific firmware or operating‑system versions, so any Snapdragon device that implements the vulnerable I/O‑control interface should be considered at risk. Refer to Qualcomm’s July 2026 security bulletin for detailed patch information and apply updates accordingly.
Risk and Exploitability
The CVSS score of 6.6 indicates moderate severity, and the EPSS score of <1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires local or privileged access to the device, as the exploit would need the specific memory map/unmap sequence. No publicly available exploits are documented, but an attacker who can manipulate the vulnerable sequence could trigger memory corruption that might destabilize the system or potentially allow arbitrary code execution. Given the moderate severity and low exploitation probability, patching the affected firmware remains the recommended action.
OpenCVE Enrichment