Description
Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchronization.
Published: 2026-07-06
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a use‑after processes I/O control calls to map and later unmap persistent memory buffers without synchronization, causing the kernel to reference memory that has already been freed, potentially leading to unpredictable memory corruption. While it is not explicitly stated whether this can be leveraged for arbitrary code execution, such memory corruption would typically allow an attacker to alter kernel state in a way that could compromise system integrity or stability.

Affected Systems

Qualcomm’s Snapdragon platform is affected. The data does not list specific firmware or operating‑system versions, so any Snapdragon device that implements the vulnerable I/O‑control interface should be considered at risk. Refer to Qualcomm’s July 2026 security bulletin for detailed patch information and apply updates accordingly.

Risk and Exploitability

The CVSS score of 6.6 indicates moderate severity, and the EPSS score of <1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires local or privileged access to the device, as the exploit would need the specific memory map/unmap sequence. No publicly available exploits are documented, but an attacker who can manipulate the vulnerable sequence could trigger memory corruption that might destabilize the system or potentially allow arbitrary code execution. Given the moderate severity and low exploitation probability, patching the affected firmware remains the recommended action.

Generated by OpenCVE AI on July 23, 2026 at 14:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the firmware or software update released by Qualcomm that addresses the improper memory synchronization issue.
  • Restrict device‑control interface usage vulnerable I/O control commands.
  • Monitor kernel logs or system events for abnormal memory mapping or unmapping activities as an indicator of potential exploitation attempts.

Generated by OpenCVE AI on July 23, 2026 at 14:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Mon, 06 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchronization.
Title Use After Free in Computer Vision
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L'}


Subscriptions

Qualcomm Snapdragon
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-07-07T13:11:29.305Z

Reserved: 2025-09-18T03:19:23.202Z

Link: CVE-2025-59615

cve-icon Vulnrichment

Updated: 2026-07-06T20:49:20.450Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T14:30:17Z

Weaknesses