Executive brief
A Qualcomm component fails to validate data received from neighboring systems, leading to an out-of-bounds memory access. This vulnerability can cause temporary service disruptions or crashes, affecting the availability of connected devices or systems that rely on this component.
Technical details
The vulnerability is an out-of-bounds memory access (CWE-119 or similar) in Qualcomm firmware or software that processes unverified data from adjacent systems. The root cause is insufficient input validation of network or inter-system communication data. The attack vector is adjacent/network-accessible, requiring data from a neighboring system to trigger the out-of-bounds read or write. An attacker can cause a denial of service through transient crashes; code execution may also be possible depending on memory layout and the nature of the out-of-bounds access. Patches are expected from Qualcomm as part of their security bulletin cycle.
Affected products
- Qualcomm <UNKNOWN>
Timeline
- 2026-09-17: disclosed