Impact
A stack‑based buffer overflow occurs in Qualcomm Snapdragon WLAN host code when it processes an invalid HT40 channel layout during dynamic channel switching operations. The overflow corrupts the stack, causing memory corruption. No evidence is provided that the vulnerability results in a crash or arbitrary code execution, but the corrupted memory could potentially be leveraged to influence system integrity if the vulnerable code runs with elevated privileges.
Affected Systems
Qualcomm Snapdragon wireless platforms that implement the described dynamic channel‑switching logic are affected. The CVE does not list precise firmware versions or device models, so any Snapdragon device that handles HT40 channel layouts in this manner may be at risk.
Risk and Exploitability
The CVSS score of 8.8 signifies a high severity. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not present in the CISA KEV catalog. Based on the description, the likely attack vector involves transmitting specially crafted Wi‑Fi frames that produce an invalid HT40 layout, which an attacker could arrange from a device in proximity or by exploiting an open wireless network, the memory corruption could enable privilege escalation or compromise of system integrity if the vulnerable code runs with sufficient privileges.
OpenCVE Enrichment