Description
Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a stack-based buffer overflow caused by copying unverified external data without checking the buffer size. The flaw allows an attacker to overwrite adjacent memory, leading to potential code execution, crashing the component, or escalating privileges. This exception falls under CWE-121 and can compromise confidentiality, integrity, or availability if exploited.

Affected Systems

Qualcomm Inc. Snapdragon devices are affected. No specific firmware or product versions were listed in the advisory; therefore, all Snapdragon builds that include the OOBM component should be treated as at risk until a patch is applied or the vendor discloses affected versions.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1 % suggests a low current exploitation probability. OOBM receives no entry in the CISA KEV catalog. Based on the description, the likely attack vector is the delivery of malformed external input—potentially over the network or a user-supplied interface—to trigger the overflow. Successful exploitation would require the attacker to provide data that exceeds the buffer size; this could be achieved remotely if the component accepts external input over an exposed channel, or locally if an attacker can craft a payload that feeds the OOBM routine.

Generated by OpenCVE AI on September 17, 2026 at 21:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available Qualcomm Snapdragon firmware update that addresses the buffer overflow flaw.
  • Restrict or block external data sources that interact with the OOBM component, or apply strict input validation to prevent malformed data from reaching the implementation.
  • Configure the system to use hardened security defaults such as stack canaries, ASLR, and bounds checking, and monitor for abnormal memory writes or application crashes.

Generated by OpenCVE AI on September 17, 2026 at 21:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm cologne
Qualcomm cologne Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 7800 Firmware
Qualcomm snapdragon X2 Elite
Qualcomm snapdragon X2 Elite Firmware
Qualcomm wcd9378c
Qualcomm wcd9378c Firmware
Qualcomm wsa8840
Qualcomm wsa8840 Firmware
Qualcomm wsa8845
Qualcomm wsa8845 Firmware
Qualcomm wsa8845h
Qualcomm wsa8845h Firmware
CPEs cpe:2.3:h:qualcomm:cologne:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_x2_elite:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9378c:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8840:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845h:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:cologne_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_x2_elite_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9378c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*
Vendors & Products Qualcomm cologne
Qualcomm cologne Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 7800 Firmware
Qualcomm snapdragon X2 Elite
Qualcomm snapdragon X2 Elite Firmware
Qualcomm wcd9378c
Qualcomm wcd9378c Firmware
Qualcomm wsa8840
Qualcomm wsa8840 Firmware
Qualcomm wsa8845
Qualcomm wsa8845 Firmware
Qualcomm wsa8845h
Qualcomm wsa8845h Firmware

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Description Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.
Title Stack-based Buffer Overflow in OOBM
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Qualcomm Cologne Cologne Firmware Fastconnect 7800 Fastconnect 7800 Firmware Snapdragon Snapdragon X2 Elite Snapdragon X2 Elite Firmware Wcd9378c Wcd9378c Firmware Wsa8840 Wsa8840 Firmware Wsa8845 Wsa8845 Firmware Wsa8845h Wsa8845h Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-09-17T14:32:53.401Z

Reserved: 2026-02-02T04:19:00.942Z

Link: CVE-2026-25283

cve-icon Vulnrichment

Updated: 2026-09-17T14:32:48.140Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T05:17:01.390

Modified: 2026-09-22T19:01:13.893

Link: CVE-2026-25283

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:15:14Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow