Impact
The flaw is a memory corruption triggered when the fastboot command handler processes untrusted user input for audio framework configuration. The improper validation of syntactic correctness may corrupt memory, leading to a crash or, potentially, execution of attacker‑controlled code. This can compromise confidentiality, integrity or availability of the automotive Linux OS system.
Affected Systems
Qualcomm Snapdragon automotive Linux operating systems are affected. The CNA data does not provide specific version numbers, so any deployment that includes the fastboot audio framework configuration component may be vulnerable.
Risk and Exploitability
The CVSS score of 7.6 indicates a high‑severity flaw. EPSS information is not available, leaving the exploitation probability uncertain. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector involves the fastboot command interface, which may be locally available or exposed remotely depending on system configuration. An attacker who can supply crafted input to this interface could trigger the memory corruption and potentially cause denial of service or enable arbitrary code execution if the corruption reaches an exploitable state.
OpenCVE Enrichment