We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-21456

Use After Free in NPU



Description

Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently.

Reserved 2024-12-18 | Published 2025-08-06 | Updated 2025-08-06 | Assigner qualcomm


HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-416 Use After Free

Product status

Default status
unaffected

AR8035
affected

C-V2X 9150
affected

FastConnect 6900
affected

FastConnect 7800
affected

QAM8255P
affected

QAM8295P
affected

QAM8650P
affected

QAM8775P
affected

QCA6174A
affected

QCA6574AU
affected

QCA6584AU
affected

QCA6696
affected

QCA6698AQ
affected

QCA6797AQ
affected

QCA8081
affected

QCA8337
affected

QCC710
affected

QCN6224
affected

QCN6274
affected

QCS410
affected

QCS610
affected

QFW7114
affected

QFW7124
affected

Qualcomm Video Collaboration VC1 Platform
affected

Qualcomm Video Collaboration VC3 Platform
affected

SA6145P
affected

SA6150P
affected

SA6155P
affected

SA7255P
affected

SA7775P
affected

SA8145P
affected

SA8150P
affected

SA8155P
affected

SA8195P
affected

SA8255P
affected

SA8295P
affected

SA8530P
affected

SA8540P
affected

SA8620P
affected

SA8650P
affected

SA8775P
affected

SA9000P
affected

Snapdragon 888 5G Mobile Platform
affected

Snapdragon 888+ 5G Mobile Platform (SM8350-AC)
affected

Snapdragon Auto 5G Modem-RF Gen 2
affected

Snapdragon W5+ Gen 1 Wearable Platform
affected

Snapdragon X72 5G Modem-RF System
affected

Snapdragon X75 5G Modem-RF System
affected

SW5100
affected

SW5100P
affected

WCD9340
affected

WCD9341
affected

WCD9370
affected

WCD9380
affected

WCD9385
affected

WCN3660B
affected

WCN3680B
affected

WCN3950
affected

WCN3980
affected

WCN3988
affected

WSA8810
affected

WSA8815
affected

WSA8830
affected

WSA8835
affected

References

docs.qualcomm.com/...uritybulletin/august-2025-bulletin.html

cve.org (CVE-2025-21456)

nvd.nist.gov (CVE-2025-21456)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-21456

Support options

Helpdesk Chat, Email, Knowledgebase