Description
Memory corruption while processing a crafted ELF file in the Primary Bootloader.
Published: 2026-09-22
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

Memory corruption occurs when the primary bootloader parses a specially crafted ELF file. The flaw can allow an attacker to overwrite critical bootloader data, potentially leading to arbitrary code execution with system‑level privileges.

Affected Systems

Qualcomm Snapdragon platforms are affected. Specific models or firmware revisions are not listed, so any Snapdragon‑based device that uses the primary bootloader with the affected code may be vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates significant severity. The EPSS score is not available, so exploitation probability is unknown; the vulnerability is not currently listed in CISA KEV. The attack vector is inferred to require delivering a crafted ELF file during the bootloader’s loading phase, such as during a firmware update or manual flashing, implying a close or physical access scenario.

Generated by OpenCVE AI on September 22, 2026 at 11:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Qualcomm firmware update that addresses the primary bootloader issue.
  • Ensure that only signed, authenticated firmware images are accepted by the bootloader.
  • Restrict physical access to the device’s flashing port or use lockout mechanisms to prevent unauthorized updates.

Generated by OpenCVE AI on September 22, 2026 at 11:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description Memory corruption while processing a crafted ELF file in the Primary Bootloader.
Title Write-what-where Condition in Primary Bootloader
Weaknesses CWE-123
References
Metrics cvssV3_1

{'score': 6.9, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-09-22T10:15:27.877Z

Reserved: 2026-02-02T04:19:00.939Z

Link: CVE-2026-25262

cve-icon Vulnrichment

Updated: 2026-09-22T10:14:24.141Z

cve-icon NVD

Status : Received

Published: 2026-09-22T10:17:08.973

Modified: 2026-09-22T11:17:24.327

Link: CVE-2026-25262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T11:30:09Z

Weaknesses
  • CWE-123

    Write-what-where Condition