Description
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.
Published: 2026-07-06
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is triggered when a Qualcomm Snapdragon kernel module processes multiple IOCTL calls that share the same buffer file‑descriptor input. The use‑after‑free condition occurs after the underlying object has already been freed, leading to memory corruption in the driver. The CVE description does not specify the precise outcome, but such corruption could cause the driver to behave unexpectedly or crash. No explicit mention of denial of service or arbitrary code execution is present.

Affected Systems

Qualcomm Snapdragon processors and their associated software stack are affected. The advisory does not list specific firmware or driver versions, so any device implementing the vulnerable image‑processing kernel module on a Snapdragon SoC could be impacted.

Risk and Exploitability

The CVSS base score of 6.6 indicates a medium risk level. The EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation would involve sending crafted IOCTL requests to the vulnerable driver. Based on the description, the likely attack vector is local, requiring the attacker to have the ability to send crafted IOCTL requests to the vulnerable driver.

Generated by OpenCVE AI on August 1, 2026 at 18:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Monitor Qualcomm’s release notes and security advisories for an update that addresses the use‑after‑free flaw.
  • Restrict the vulnerable kernel module’s IOCTL interface to trusted processes by configuring appropriate capabilities or kernel‑level access controls.
  • Enable advanced security frameworks such as SELinux or AppArmor to limit the impact scope of the driver.
  • Apply memory‑management safeguards consistent with CWE‑416 recommendations, ensuring that freed objects are not accessed while still in use.

Generated by OpenCVE AI on August 1, 2026 at 18:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.
Title Use After Free in Computer Vision
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L'}


Subscriptions

Qualcomm Fastconnect 6700 Fastconnect 6700 Firmware Fastconnect 6900 Fastconnect 6900 Firmware Fastconnect 7800 Fastconnect 7800 Firmware Molokai Molokai Firmware Orne Orne Firmware Pandeiro Pandeiro Firmware Qcm5430 Qcm5430 Firmware Qcm6490 Qcm6490 Firmware Qmp1000 Qmp1000 Firmware Qmp2001 Qmp2001 Firmware Sc8380xp Sc8380xp Firmware Sd865 5g Sd865 5g Firmware Sm6850 Sm6850 Firmware Sm8845p Sm8845p Firmware Snapdragon Snapdragon 460 Mobile Platform Snapdragon 460 Mobile Platform Firmware Snapdragon 662 Mobile Platform Snapdragon 662 Mobile Platform Firmware Snapdragon 8 Elite Gen 5 Snapdragon 8 Elite Gen 5 Firmware Snapdragon Ar1 Gen 1 Platform Snapdragon Ar1 Gen 1 Platform Firmware Snapdragon Xr2\+ Gen 1 Platform Snapdragon Xr2\+ Gen 1 Platform Firmware Snapdragon Xr2 5g Platform Snapdragon Xr2 5g Platform Firmware Sxr2230p Sxr2230p Firmware Sxr2250p Sxr2250p Firmware Video Collaboration Vc3 Platform Video Collaboration Vc3 Platform Firmware Wcd9370 Wcd9370 Firmware Wcd9375 Wcd9375 Firmware Wcd9378 Wcd9378 Firmware Wcd9380 Wcd9380 Firmware Wcd9385 Wcd9385 Firmware Wcd9395 Wcd9395 Firmware Wcn3950 Wcn3950 Firmware Wcn3988 Wcn3988 Firmware Wcn6450 Wcn6450 Firmware Wcn7760 Wcn7760 Firmware Wcn7860 Wcn7860 Firmware Wcn7861 Wcn7861 Firmware Wcn7880 Wcn7880 Firmware Wcn7881 Wcn7881 Firmware Wsa8810 Wsa8810 Firmware Wsa8815 Wsa8815 Firmware Wsa8830 Wsa8830 Firmware Wsa8832 Wsa8832 Firmware Wsa8835 Wsa8835 Firmware Wsa8840 Wsa8840 Firmware Wsa8845 Wsa8845 Firmware Wsa8845h Wsa8845h Firmware Wsa8850 Wsa8850 Firmware Wsa8850w Wsa8850w Firmware Wsa8855c Wsa8855c Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-07-07T13:11:08.093Z

Reserved: 2025-09-18T03:19:23.202Z

Link: CVE-2025-59617

cve-icon Vulnrichment

Updated: 2026-07-06T20:54:02.991Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-06T21:16:52.653

Modified: 2026-07-07T16:59:44.367

Link: CVE-2025-59617

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T18:15:04Z

Weaknesses