01 Record
CVE-2026-25280
Out-of-bounds Write in DSP Service
HighPUBLISHEDCNA: qualcomm
CNA base score7.8 CVSS v3.xCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
02 Description
Out-of-bounds Write in DSP Service
03 Exploitation and scoring
- Exploitation
- Not assessed. CISA has not published an exploitation assessment for this record, and it is not in the KEV catalog. That is an absence of assessment, not a finding of no risk.
- SSVC decision
- Not assessed by CISA
- EPSS probability
- Not scored by EPSS
- EPSS percentile
- Not scored by EPSS
- NVD base score
- 7.8 (CVSS v3.x), scored by the NVD independently of the CNA.
- NVD CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- NVD analysis status
- Received. NVD last modified this record on 2026-09-17.
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
04 Metadata
- Published
- 2026-09-17 04:11Z2 HR AGO
- Last updated
- 2026-09-17 04:11Z2 HR AGO
- Reserved
- 2026-02-02
- Assigning CNA
- qualcomm
- Record state
- PUBLISHED
- Severity
- High (CVSS 7.8)
- CNA CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Weaknesses
- CWE-787Out-of-bounds WriteBase
- Data version
- 5.2
- Document digest
- 31435d972935b4f600b8ab544a5e31340a1e7b593041f6329b6b26a91f8615cf
05 Affected products
VendorProductVersionsPlatforms
Qualcomm, Inc.SnapdragonCologne, FastConnect 6700, FastConnect 6900, FastConnect 7800, IQX5121, IQX7181, QCA0000, QCM5430, QCM6490, Qualcomm Video Collaboration VC3 Platform, SC8380XP, Snapdragon X2 Elite, WCD9370, WCD9375, WCD9378C, WCD9380, WCD9385, WSA8840, WSA8845, WSA8845HSnapdragon Compute, Snapdragon Industrial IOT