Description
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory.
Published: 2026-07-06
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use-after-free flaw exists in the Snapdragon driver when it handles repeated IOCTL calls that share the same buffer file descriptor. The driver later accesses memory that has already been freed, resulting in memory corruption. The weakness is classified as CWE-416 and may allow an attacker to corrupt device or system memory, potentially leading to device crashes or unintended behavior.

Affected Systems

All Qualcomm Snapdragon chipsets or firmware that process IOCTL calls using shared buffer file descriptors are impacted. The advisory does not disclose specific chipset or firmware versions, so the attack surface includes any Snapdragon driver that allows reuse of buffer FDs across multiple IOCTL requests.

Risk and Exploitability

The CVSS score of 6.6 indicates moderate severity, while the EPSS score of <1% shows a very low probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector requires an attacker with the ability to issue privileged IOCTL commands to the driver, implying that a privileged or local attacker could exploit the flaw to compromise device memory integrity or availability.

Generated by OpenCVE AI on August 1, 2026 at 18:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Qualcomm Snapdragon firmware update that addresses the memory corruption issue
  • Restrict use of privileged IOCTL interfaces so that only trusted system components can access the affected driver
  • Avoid reusing buffer file descriptors across multiple IOCTL calls in applications whenever possible

Generated by OpenCVE AI on August 1, 2026 at 18:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Mon, 06 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory.
Title Use After Free in Computer Vision
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L'}


Subscriptions

Qualcomm Fastconnect 6700 Fastconnect 6700 Firmware Fastconnect 6900 Fastconnect 6900 Firmware Fastconnect 7800 Fastconnect 7800 Firmware Molokai Molokai Firmware Orne Orne Firmware Pandeiro Pandeiro Firmware Qcm5430 Qcm5430 Firmware Qcm6490 Qcm6490 Firmware Qmp1000 Qmp1000 Firmware Qmp2001 Qmp2001 Firmware Sc8380xp Sc8380xp Firmware Sd865 5g Sd865 5g Firmware Sm6850 Sm6850 Firmware Sm8845p Sm8845p Firmware Snapdragon Snapdragon 460 Mobile Platform Snapdragon 460 Mobile Platform Firmware Snapdragon 662 Mobile Platform Snapdragon 662 Mobile Platform Firmware Snapdragon 8 Elite Gen 5 Snapdragon 8 Elite Gen 5 Firmware Snapdragon Ar1 Gen 1 Platform Snapdragon Ar1 Gen 1 Platform Firmware Snapdragon Xr2\+ Gen 1 Platform Snapdragon Xr2\+ Gen 1 Platform Firmware Snapdragon Xr2 5g Platform Snapdragon Xr2 5g Platform Firmware Sxr2230p Sxr2230p Firmware Sxr2250p Sxr2250p Firmware Video Collaboration Vc3 Platform Video Collaboration Vc3 Platform Firmware Wcd9370 Wcd9370 Firmware Wcd9375 Wcd9375 Firmware Wcd9378 Wcd9378 Firmware Wcd9380 Wcd9380 Firmware Wcd9385 Wcd9385 Firmware Wcd9395 Wcd9395 Firmware Wcn3950 Wcn3950 Firmware Wcn3988 Wcn3988 Firmware Wcn6450 Wcn6450 Firmware Wcn7760 Wcn7760 Firmware Wcn7860 Wcn7860 Firmware Wcn7861 Wcn7861 Firmware Wcn7880 Wcn7880 Firmware Wcn7881 Wcn7881 Firmware Wsa8810 Wsa8810 Firmware Wsa8815 Wsa8815 Firmware Wsa8830 Wsa8830 Firmware Wsa8832 Wsa8832 Firmware Wsa8835 Wsa8835 Firmware Wsa8840 Wsa8840 Firmware Wsa8845 Wsa8845 Firmware Wsa8845h Wsa8845h Firmware Wsa8850 Wsa8850 Firmware Wsa8850w Wsa8850w Firmware Wsa8855c Wsa8855c Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-07-07T13:11:17.423Z

Reserved: 2025-09-18T03:19:23.202Z

Link: CVE-2025-59616

cve-icon Vulnrichment

Updated: 2026-07-06T20:53:43.276Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-06T21:16:52.513

Modified: 2026-07-07T17:00:24.487

Link: CVE-2025-59616

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T18:30:04Z

Weaknesses