Description
Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
Published: 2026-09-17
Score: 7.9 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via out-of-bounds read
Action: Monitor
AI Analysis

Impact

The vulnerability is an out‑of‑bounds read (CWE‑125) triggered when Snapdragon devices process unverified data from a neighboring system, causing a transient denial‑of‑service by reading outside allocated memory. This can result in application crashes or device instability, compromising availability. The flaw does not suggest any direct information leakage or other impact.

Affected Systems

Qualcomm Snapdragon devices are affected. The advisory does not specify affected firmware or hardware revisions, so all current Snapdragon implementations that accept inter‑system data are potentially vulnerable until the vendor issues a fix.

Risk and Exploitability

With a CVSS score of 7.9, the flaw presents a high severity rating. The EPSS score indicates a very low exploitation probability (<1 %), and it is not listed in CISA KEV, suggesting no publicly known exploit currently. The attack vector is inferred to be local or nearby systems that can send malicious data before the Snapdragon device processes it; the flaw does not appear to be exploitable remotely over the internet. Until a patch is released, the primary risk is local denial of service which can affect devices connected in the same physical or logical network segment.

Generated by OpenCVE AI on September 17, 2026 at 21:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Qualcomm firmware updates as soon as the vendor provides a patch addressing the out-of-bounds read in OOBM.
  • Restrict inter-device communication by placing Snapdragon devices on a segregated network segment or firewalling untrusted data sources.
  • Monitor device logs and system performance for sudden memory access errors or crashes that could indicate an exploitation attempt, and configure alerts for such events.
  • If a temporary workaround is later published by Qualcomm, apply it according to the vendor’s instructions while awaiting the official patch.

Generated by OpenCVE AI on September 17, 2026 at 21:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm cologne
Qualcomm cologne Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 7800 Firmware
Qualcomm snapdragon X2 Elite
Qualcomm snapdragon X2 Elite Firmware
Qualcomm wcd9378c
Qualcomm wcd9378c Firmware
Qualcomm wsa8840
Qualcomm wsa8840 Firmware
Qualcomm wsa8845
Qualcomm wsa8845 Firmware
Qualcomm wsa8845h
Qualcomm wsa8845h Firmware
CPEs cpe:2.3:h:qualcomm:cologne:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_x2_elite:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9378c:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8840:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845h:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:cologne_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_x2_elite_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9378c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*
Vendors & Products Qualcomm cologne
Qualcomm cologne Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 7800 Firmware
Qualcomm snapdragon X2 Elite
Qualcomm snapdragon X2 Elite Firmware
Qualcomm wcd9378c
Qualcomm wcd9378c Firmware
Qualcomm wsa8840
Qualcomm wsa8840 Firmware
Qualcomm wsa8845
Qualcomm wsa8845 Firmware
Qualcomm wsa8845h
Qualcomm wsa8845h Firmware

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Description Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
Title Out-of-bounds Read in OOBM
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H'}


Subscriptions

Qualcomm Cologne Cologne Firmware Fastconnect 7800 Fastconnect 7800 Firmware Snapdragon Snapdragon X2 Elite Snapdragon X2 Elite Firmware Wcd9378c Wcd9378c Firmware Wsa8840 Wsa8840 Firmware Wsa8845 Wsa8845 Firmware Wsa8845h Wsa8845h Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-09-17T14:33:53.097Z

Reserved: 2026-02-02T04:19:00.942Z

Link: CVE-2026-25282

cve-icon Vulnrichment

Updated: 2026-09-17T14:33:20.683Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T05:17:01.253

Modified: 2026-09-22T19:01:01.150

Link: CVE-2026-25282

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:00:16Z

Weaknesses