CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-21468: Out-of-bounds Write in Computer Vision

7.8 CVSS

Description

Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.

Classification

CVE ID: CVE-2025-21468

CVSS Base Severity: HIGH

CVSS Base Score: 7.8

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem Types

CWE-787: Out-of-bounds Write

Affected Products

Vendor: Qualcomm, Inc.

Product: Snapdragon

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.01% (probability of being exploited)

EPSS Percentile: 1.33% (scored less or equal to compared to others)

EPSS Date: 2025-06-04 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-21468
https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2025-bulletin.html

Timeline