Impact
The flaw lies in how OOBM handles large or numerous request buffers when no validation is performed to limit memory allocation. As a result, a malicious or malformed input can exhaust memory and crash or otherwise disrupt the operation, leading to a transient denial of service. The weakness is classified as CWE‑770, which highlights that system resources are allocated without limits or throttling, allowing an attacker to destabilize availability.
Affected Systems
Qualcomm, Inc. Snapdragon devices are affected. No specific firmware or OS version information is provided in the advisory, so all Snapdragon products that implement OOBM are potentially vulnerable unless a patch has been applied.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity impact, but the EPSS score of less than 1% suggests that observed exploitation is currently rare or unlikely. The vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that an attacker would need to craft special request buffers processed by OOBM, likely requiring local or privileged access to the device. The impact would be loss of availability of the component or service that relies on OOBM; no evidence points to persistence or compromise of data integrity.
OpenCVE Enrichment