CVE-2025-21436: Use After Free in DSP Service
Published Apr 7, 2025
·Updated
Memory corruption may occur while initiating two IOCTL calls simultaneously to create processes from two different threads.
Affected Software
51 affected components
All of the following
Qualcomm Fastconnect 7800 Firmware
Qualcomm Fastconnect 7800
All of the following
Qualcomm Qmp1000 Firmware
Qualcomm Qmp1000
All of the following
Qualcomm Sm8735 Firmware
Qualcomm Sm8735
All of the following
Qualcomm Sm8750 Firmware
Qualcomm Sm8750
All of the following
Qualcomm Sm8750p Firmware
Qualcomm Sm8750p
All of the following
Qualcomm Snapdragon 8 Gen 3 Mobile Platform Firmware
Qualcomm Snapdragon 8 Gen 3 Mobile Platform
All of the following
Qualcomm Snapdragon W5\+ Gen 1 Wearable Platform Firmware
Qualcomm Snapdragon W5\+ Gen 1 Wearable Platform
All of the following
Qualcomm Sw5100 Firmware
Qualcomm Sw5100
All of the following
Qualcomm Sw5100p Firmware
Qualcomm Sw5100p
All of the following
Qualcomm Sxr2330p Firmware
Qualcomm Sxr2330p
All of the following
Qualcomm Wcd9378 Firmware
Qualcomm Wcd9378
All of the following
Qualcomm Wcd9380 Firmware
Qualcomm Wcd9380
All of the following
Qualcomm Wcd9390 Firmware
Qualcomm Wcd9390
All of the following
Qualcomm Wcd9395 Firmware
Qualcomm Wcd9395
All of the following
Qualcomm Wcn7750 Firmware
Qualcomm Wcn7750
All of the following
Qualcomm Wcn7860 Firmware
Qualcomm Wcn7860
All of the following
Qualcomm Wcn7861 Firmware
Qualcomm Wcn7861
All of the following
Qualcomm Wcn7880 Firmware
Qualcomm Wcn7880
All of the following
Qualcomm Wcn7881 Firmware
Qualcomm Wcn7881
All of the following
Qualcomm Wsa8830 Firmware
Qualcomm Wsa8830
All of the following
Qualcomm Wsa8832 Firmware
Qualcomm Wsa8832
All of the following
Qualcomm Wsa8835 Firmware
Qualcomm Wsa8835
All of the following
Qualcomm Wsa8840 Firmware
Qualcomm Wsa8840
All of the following
Qualcomm Wsa8845 Firmware
Qualcomm Wsa8845
All of the following
Qualcomm Wsa8845h Firmware
Qualcomm Wsa8845h
Google Android
Event History
Apr 7, 2025
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityAffected Software
CVE Published
via MITRE·10:16 AM
Data Sourced
via MITRE·10:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-21436?
CVE-2025-21436 is classified as a high-severity vulnerability due to the potential for memory corruption when initiating simultaneous IOCTL calls.
2
How do I fix CVE-2025-21436?
To fix CVE-2025-21436, apply the latest software patch provided by Qualcomm for affected firmware versions.
3
Which devices are impacted by CVE-2025-21436?
CVE-2025-21436 affects various Qualcomm firmware platforms, including Fastconnect 7800, Qmp1000, and Snapdragon models.
4
Is CVE-2025-21436 a remote exploit?
CVE-2025-21436 requires local access as it involves initiating IOCTL calls from different threads.
5
What are the potential impacts of CVE-2025-21436?
Exploitation of CVE-2025-21436 could lead to system instability and unpredictable behavior due to memory corruption.