Description
Memory Corruption when validating large data buffers from external sources using addition to check buffer length.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption
Action: Patch Update
AI Analysis

Impact

A bug in Snapdragon’s OOBM component causes an integer overflow or wraparound when validating large data buffers from external sources. The addition used to check buffer length can exceed the maximum value of the integer type, leading to memory corruption. An attacker could exploit this by sending specially crafted data, potentially allowing escalation of privileges or execution of arbitrary code if the overflow corrupts control flows.

Affected Systems

Qualcomm Snapdragon processors are affected. The specific firmware or kernel versions are not disclosed in the advisory, so any Snapdragon device running the involved OOBM component is potentially vulnerable. Users of Qualcomm hardware should consult the September 2026 security bulletin for version details.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, but the EPSS score is below 1 %, suggesting a low likelihood of active exploitation at present. The vulnerability is not listed in the CISA KEV catalog, so no confirmed exploits are reported. If an attacker can supply input to the OOBM component, the overflow may enable remote or local code execution depending on the privilege level of the affected process.

Generated by OpenCVE AI on September 17, 2026 at 21:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the firmware or driver update published by Qualcomm in the September 2026 security bulletin to correct the integer overflow in Snapdragon.
  • Restrict or disable any services that allow untrusted data to be passed to OOBM, ensuring only trusted data sources can reach the vulnerable code path.
  • Add or enforce bounds checking on buffer lengths before performing arithmetic operations in any custom firmware or application that interfaces with Snapdragon’s OOBM.

Generated by OpenCVE AI on September 17, 2026 at 21:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm cologne
Qualcomm cologne Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 7800 Firmware
Qualcomm snapdragon X2 Elite
Qualcomm snapdragon X2 Elite Firmware
Qualcomm wcd9378c
Qualcomm wcd9378c Firmware
Qualcomm wsa8840
Qualcomm wsa8840 Firmware
Qualcomm wsa8845
Qualcomm wsa8845 Firmware
Qualcomm wsa8845h
Qualcomm wsa8845h Firmware
CPEs cpe:2.3:h:qualcomm:cologne:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:fastconnect_7800:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:snapdragon_x2_elite:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wcd9378c:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8840:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:wsa8845h:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:cologne_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:snapdragon_x2_elite_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wcd9378c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8840_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:qualcomm:wsa8845h_firmware:-:*:*:*:*:*:*:*
Vendors & Products Qualcomm cologne
Qualcomm cologne Firmware
Qualcomm fastconnect 7800
Qualcomm fastconnect 7800 Firmware
Qualcomm snapdragon X2 Elite
Qualcomm snapdragon X2 Elite Firmware
Qualcomm wcd9378c
Qualcomm wcd9378c Firmware
Qualcomm wsa8840
Qualcomm wsa8840 Firmware
Qualcomm wsa8845
Qualcomm wsa8845 Firmware
Qualcomm wsa8845h
Qualcomm wsa8845h Firmware

Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Description Memory Corruption when validating large data buffers from external sources using addition to check buffer length.
Title Integer Overflow or Wraparound in OOBM
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Qualcomm Cologne Cologne Firmware Fastconnect 7800 Fastconnect 7800 Firmware Snapdragon Snapdragon X2 Elite Snapdragon X2 Elite Firmware Wcd9378c Wcd9378c Firmware Wsa8840 Wsa8840 Firmware Wsa8845 Wsa8845 Firmware Wsa8845h Wsa8845h Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-09-17T12:44:24.010Z

Reserved: 2026-02-02T04:19:00.942Z

Link: CVE-2026-25290

cve-icon Vulnrichment

Updated: 2026-09-17T12:44:15.775Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T05:17:01.650

Modified: 2026-09-22T19:01:39.993

Link: CVE-2026-25290

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:00:16Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound