Impact
The DSP Service contains a classic time‑of‑check time‑of‑use race condition that allows an attacker to modify asynchronous input parameters after the service performs validation but before they are actually used. This flaw is classified as CWE‑367 and leads to memory corruption within the DSP Service context; a direct claim of privilege escalation is not supported by the CVE text.
Affected Systems
Qualcomm Snapdragon processor families that include the DSP Service are potentially affected. No specific firmware revision or hardware version is listed, meaning any device that incorporates this service may be vulnerable and should be audited or updated.
Risk and Exploitability
The CVSS score of 7.8 places the vulnerability in the High severity range. The EPSS score of less than 1% indicates that, while exploitation is unlikely, it is not impossible. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local or remote application that can supply asynchronous input to the DSP Service; the description does not specify required privileges, so it is inferred that any process that can interact with the service could potentially exploit the race condition. Until mitigated, the risk remains.
OpenCVE Enrichment