Impact
Concurrent DMA buffer allocation and deallocation commands are processed without proper synchronization, causing a use‑after‑free during WLAN host operations. This memory corruption can enable an attacker to manipulate the device’s memory state, potentially leading to arbitrary code execution or denial of service. The flaw is classified as CWE‑416, indicating a use‑after‑free vulnerability.
Affected Systems
Qualcomm, Inc. Snapdragon products are affected. No specific firmware or SDK versions are listed in the advisory.
Risk and Exploitability
The CVSS base score of 6.7 reflects a moderate severity risk, indicating that an attacker could achieve a significant impact if the flaw is exploited. The EPSS score is not available, but the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is inferred to involve local or privileged access capable of triggering concurrent DMA buffer operations on the WLAN host; an attacker would need to provoke the race condition to cause the use‑after‑free.
OpenCVE Enrichment