Description
Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.
Published: 2026-09-17
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Transient)
Action: Patch Now
AI Analysis

Impact

The flaw lies in how OOBM handles large or numerous request buffers when no validation is performed to limit memory allocation. As a result, a malicious or malformed input can exhaust memory and crash or otherwise disrupt the operation, leading to a transient denial of service. The weakness is classified as CWE‑770, which highlights that system resources are allocated without limits or throttling, allowing an attacker to destabilize availability.

Affected Systems

Qualcomm, Inc. Snapdragon devices are affected. No specific firmware or OS version information is provided in the advisory, so all Snapdragon products that implement OOBM are potentially vulnerable unless a patch has been applied.

Risk and Exploitability

The CVSS score of 7.4 indicates a high severity impact, but the EPSS score of less than 1% suggests that observed exploitation is currently rare or unlikely. The vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that an attacker would need to craft special request buffers processed by OOBM, likely requiring local or privileged access to the device. The impact would be loss of availability of the component or service that relies on OOBM; no evidence points to persistence or compromise of data integrity.

Generated by OpenCVE AI on September 17, 2026 at 21:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Qualcomm firmware or software update that addresses the resource allocation issue in OOBM on Snapdragon devices.
  • If a patch is not yet available, limit or disable the processing of large or numerous request buffers through device configuration or network policy to reduce the risk of memory exhaustion.
  • Implement network segmentation or firewall rules to restrict external entities from sending large or frequent requests to the affected component.
  • Monitor device logs for errors related to memory allocation failures or OOBM crashes to detect potential exploitation attempts.

Generated by OpenCVE AI on September 17, 2026 at 21:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm cologne
Qualcomm cologne Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 7800 Firmware
Qualcomm snapdragon X2 Elite
Qualcomm snapdragon X2 Elite Firmware
Qualcomm wcd9378c
Qualcomm wcd9378c Firmware
Qualcomm wsa8840
Qualcomm wsa8840 Firmware
Qualcomm wsa8845
Qualcomm wsa8845 Firmware
Qualcomm wsa8845h
Qualcomm wsa8845h Firmware
CPEs cpe:2.3:h:qualcomm:cologne:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_x2_elite:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9378c:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8840:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845h:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:cologne_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_x2_elite_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9378c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*
Vendors & Products Qualcomm cologne
Qualcomm cologne Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 7800 Firmware
Qualcomm snapdragon X2 Elite
Qualcomm snapdragon X2 Elite Firmware
Qualcomm wcd9378c
Qualcomm wcd9378c Firmware
Qualcomm wsa8840
Qualcomm wsa8840 Firmware
Qualcomm wsa8845
Qualcomm wsa8845 Firmware
Qualcomm wsa8845h
Qualcomm wsa8845h Firmware

Thu, 17 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Description Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.
Title Allocation of Resources Without Limits or Throttling in OOBM
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Qualcomm Cologne Cologne Firmware Fastconnect 7800 Fastconnect 7800 Firmware Snapdragon Snapdragon X2 Elite Snapdragon X2 Elite Firmware Wcd9378c Wcd9378c Firmware Wsa8840 Wsa8840 Firmware Wsa8845 Wsa8845 Firmware Wsa8845h Wsa8845h Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-09-17T14:38:24.747Z

Reserved: 2026-02-02T04:19:00.941Z

Link: CVE-2026-25281

cve-icon Vulnrichment

Updated: 2026-09-17T14:38:16.239Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T05:17:01.120

Modified: 2026-09-22T19:00:52.657

Link: CVE-2026-25281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:00:16Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling