CVE-2025-21433: NULL Pointer Dereference in SPS-HLOS
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21433?
The severity of CVE-2025-21433 is classified as high due to the potential for transient denial of service when importing a malformed RSA private key.
How does CVE-2025-21433 affect Qualcomm firmware?
CVE-2025-21433 affects multiple Qualcomm firmware versions, causing denial of service vulnerabilities when processing PKCS#8-encoded RSA private keys.
What are the potential impacts of CVE-2025-21433?
The potential impact of CVE-2025-21433 includes system crashes or freezing in devices using the affected Qualcomm firmware.
How can I mitigate CVE-2025-21433?
To mitigate CVE-2025-21433, users should update their Qualcomm firmware to the latest version provided by the manufacturer that addresses this vulnerability.
Is there a patch available for CVE-2025-21433?
Yes, Qualcomm has released patches in security bulletins to address CVE-2025-21433 for affected firmware versions.