Description
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
Published: 2026-08-04
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack‑based buffer overflow exists in Qualcomm Snapdragon WLAN firmware when the device processes Device Capability Extended attributes in certain NAN Service Discovery Frames that contain invalid length values. The overflow corrupts memory on the stack, creating a vulnerability that could allow an attacker to execute arbitrary code or cause a denial of service on the affected device. The weakness is classified as CWE‑121 (Stack-based Buffer Overflow).

Affected Systems

Qualcomm Snapdragon devices that run the WLAN firmware containing the vulnerability. No specific model or firmware version information is provided, so all versions that include the affected code should be presumed vulnerable.

Risk and Exploitability

The CVSS score of 9.6 indicates a critical severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker transmitting specially crafted NAN Service Discovery Frames to a nearby device over the wireless network; such frames would trigger the overflow during packet parsing. Given the critical score and the lack of a publicly documented exploit, the risk remains high pending a vendor fix.

Generated by OpenCVE AI on August 4, 2026 at 19:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Inquire with Qualcomm for a firmware update that resolves the buffer overflow.
  • Apply the updated firmware to all affected Qualcomm Snapdragon devices as soon as it is available.
  • If an update is not yet available, disable the NAN Service Discovery feature or block its frames using wireless network ACLs or segmentation to mitigate exposure.

Generated by OpenCVE AI on August 4, 2026 at 19:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
Title Stack-based Buffer Overflow in WLAN Firmware
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-08-04T15:50:23.901Z

Reserved: 2026-02-02T04:19:00.942Z

Link: CVE-2026-25289

cve-icon Vulnrichment

Updated: 2026-08-04T15:50:19.549Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T19:45:03Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow