Description
Memory Corruption when processing concurrent DMA buffer allocation and deallocation commands without proper synchronization.
Published: 2026-10-06
Score: 6.7 Medium
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Concurrent DMA buffer allocation and deallocation commands are processed without proper synchronization, causing a use‑after‑free during WLAN host operations. This memory corruption can enable an attacker to manipulate the device’s memory state, potentially leading to arbitrary code execution or denial of service. The flaw is classified as CWE‑416, indicating a use‑after‑free vulnerability.

Affected Systems

Qualcomm, Inc. Snapdragon products are affected. No specific firmware or SDK versions are listed in the advisory.

Risk and Exploitability

The CVSS base score of 6.7 reflects a moderate severity risk, indicating that an attacker could achieve a significant impact if the flaw is exploited. The EPSS score is not available, but the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is inferred to involve local or privileged access capable of triggering concurrent DMA buffer operations on the WLAN host; an attacker would need to provoke the race condition to cause the use‑after‑free.

Generated by OpenCVE AI on October 6, 2026 at 08:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑released fix for the DMA buffer synchronization issue.
  • Restrict concurrent DMA buffer operations to privileged processes or add kernel‐level checks to prevent unsynchronized deallocations.
  • Monitor for crashes or anomalous memory behavior that may indicate exploitation attempts.

Generated by OpenCVE AI on October 6, 2026 at 08:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description Memory Corruption when processing concurrent DMA buffer allocation and deallocation commands without proper synchronization.
Title Use After Free in Windows WLAN Host
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-10-06T06:29:49.570Z

Reserved: 2026-02-02T04:19:00.941Z

Link: CVE-2026-25274

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T07:16:57.770

Modified: 2026-10-06T07:16:57.770

Link: CVE-2026-25274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T08:30:18Z

Weaknesses