CVE-2025-21468: Out-of-bounds Write in Computer Vision
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21468?
CVE-2025-21468 has been classified as high severity due to the potential for memory corruption leading to denial of service or arbitrary code execution.
How do I fix CVE-2025-21468?
To mitigate CVE-2025-21468, update to the latest firmware versions provided by Qualcomm that address this memory corruption vulnerability.
Which devices are affected by CVE-2025-21468?
CVE-2025-21468 affects several Qualcomm firmware components, including AR8035, CSRA6620, and WCD series firmware.
What does CVE-2025-21468 vulnerability impact?
This vulnerability can lead to memory corruption when firmware writes a null character inappropriately, affecting system stability and security.
When was CVE-2025-21468 disclosed?
CVE-2025-21468 was disclosed in May 2025 as part of Qualcomm's security bulletin.