CVE-2025-21486: Untrusted Pointer Dereference in DSP Service
Memory corruption during dynamic process creation call when client is only passing address and length of shell binary.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21486?
CVE-2025-21486 is classified as a memory corruption vulnerability that poses significant risk to affected devices.
How do I fix CVE-2025-21486?
To address CVE-2025-21486, apply the latest firmware updates from Qualcomm that patch the vulnerability.
Which devices are affected by CVE-2025-21486?
CVE-2025-21486 specifically affects Qualcomm firmware for devices such as Fastconnect 6900, Fastconnect 7800, and others listed in the affected software section.
What kind of attacks can exploit CVE-2025-21486?
Exploitation of CVE-2025-21486 can lead to remote code execution or system instability during dynamic process creation.
Is there a workaround for CVE-2025-21486 if updates cannot be applied immediately?
As a temporary measure, minimizing exposure by disabling affected services may reduce the risk until a fix can be applied for CVE-2025-21486.