Impact
Memory corruption occurs when the Snapdragon device driver processes IOCTL requests with malformed arguments. The driver dereferences untrusted pointers, allowing an attacker to supply crafted data that writes to arbitrary memory locations. If an attacker can trigger the vulnerable ioctl, they might execute arbitrary code or elevate privileges on the affected system, compromising confidentiality, integrity, and availability.
Affected Systems
This flaw is present in Qualcomm, Inc. Snapdragon components that include the affected device driver. The exact component version is not provided in the advisory, but all Snapdragon platforms using the current driver build from Qualcomm are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS 7.8 score indicates a medium‑to‑high severity vulnerability. EPSS data is unavailable, so a precise exploitation probability cannot be quantified, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be local: an unauthenticated local process that can issue raw ioctl calls may trigger the flaw. Because the flaw involves memory corruption, exploit development is non‑trivial and likely requires kernel‑level expertise, but once achieved it could lead to full system compromise.
OpenCVE Enrichment