Impact
A stack‑based buffer overflow exists in Qualcomm Snapdragon WLAN firmware when the device processes Device Capability Extended attributes in certain NAN Service Discovery Frames that contain invalid length values. The overflow corrupts memory on the stack, creating a vulnerability that could allow an attacker to execute arbitrary code or cause a denial of service on the affected device. The weakness is classified as CWE‑121 (Stack-based Buffer Overflow).
Affected Systems
Qualcomm Snapdragon devices that run the WLAN firmware containing the vulnerability. No specific model or firmware version information is provided, so all versions that include the affected code should be presumed vulnerable.
Risk and Exploitability
The CVSS score of 9.6 indicates a critical severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker transmitting specially crafted NAN Service Discovery Frames to a nearby device over the wireless network; such frames would trigger the overflow during packet parsing. Given the critical score and the lack of a publicly documented exploit, the risk remains high pending a vendor fix.
OpenCVE Enrichment