CVE-2025-21456: Use After Free in NPU
Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21456?
CVE-2025-21456 has been assessed as a high-severity vulnerability due to the potential for memory corruption.
How do I fix CVE-2025-21456?
To address CVE-2025-21456, apply the latest firmware updates provided by Qualcomm that address the memory corruption issue.
Which devices are impacted by CVE-2025-21456?
CVE-2025-21456 affects various Qualcomm devices, particularly those running specific firmware versions related to the AR8035, C-v2x 9150, and Fastconnect series.
What are the potential impacts of CVE-2025-21456?
The impacts of CVE-2025-21456 include possible system crashes and exploitation that may allow unauthorized access to sensitive data.
Is there a workaround for CVE-2025-21456?
Currently, no effective workaround for CVE-2025-21456 is recommended other than updating firmware to the latest versions.