Home

Description

Memory corruption while processing config_dev IOCTL when camera kernel driver drops its reference to CPU buffers.

PUBLISHED Reserved 2025-02-18 | Published 2025-09-24 | Updated 2025-09-25 | Assigner qualcomm




HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-416 Use After Free

Product status

Default status
unaffected

FastConnect 6800
affected

FastConnect 6900
affected

FastConnect 7800
affected

QAM8295P
affected

QCA6391
affected

QCA6426
affected

QCA6436
affected

QCA6574AU
affected

QCA6696
affected

QCN9074
affected

SA6145P
affected

SA6150P
affected

SA6155P
affected

SA8145P
affected

SA8150P
affected

SA8155P
affected

SA8195P
affected

SA8295P
affected

SD865 5G
affected

Snapdragon 8 Gen 1 Mobile Platform
affected

Snapdragon 865 5G Mobile Platform
affected

Snapdragon 865+ 5G Mobile Platform (SM8250-AB)
affected

Snapdragon 870 5G Mobile Platform (SM8250-AC)
affected

Snapdragon X55 5G Modem-RF System
affected

Snapdragon XR2 5G Platform
affected

SW5100
affected

SW5100P
affected

SXR2130
affected

WCD9380
affected

WCN3660B
affected

WCN3680B
affected

WCN3980
affected

WCN3988
affected

WSA8810
affected

WSA8815
affected

WSA8830
affected

WSA8835
affected

References

docs.qualcomm.com/...tybulletin/september-2025-bulletin.html

cve.org (CVE-2025-27037)

nvd.nist.gov (CVE-2025-27037)

Download JSON