CVE-2026-25277: Buffer Copy Without Checking Size of Input in Secure Processor
Memory corruption while using Strongbox due to buffer overflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable Strongbox in the Secure Processor until a vendor-provided fix is available to avoid triggering the buffer overflow described (memory corruption while using Strongbox).
Secure Processor / Strongbox Strongbox usage = disabled - Compensating control
Prevent untrusted or oversized input from reaching the Secure Processor when Strongbox functionality is enabled — for example, apply input size validation at upstream components, isolate the Secure Processor network access, or block Strongbox-related interfaces via firewall/ACLs until a proper patch is released.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25277?
CVE-2026-25277 has a high severity rating of 8.8.
What type of vulnerability is associated with CVE-2026-25277?
CVE-2026-25277 is a buffer overflow vulnerability in Secure Processor.
What devices are affected by CVE-2026-25277?
CVE-2026-25277 affects several Qualcomm firmware versions including Cq8750m, Fastconnect 6700, 6800, 6900, 7800, G3x Gen 2, Pandeiro, and Qca6391.
How do I mitigate CVE-2026-25277?
To mitigate CVE-2026-25277, update the affected Qualcomm firmware to the latest version as recommended by the vendor.
What are the potential impacts of CVE-2026-25277?
The potential impacts of CVE-2026-25277 include memory corruption, which could lead to crashes or unauthorized access.