CVE-2026-57554: Use After Free in DSP Service
Published Oct 6, 2026
·Updated
Memory Corruption when asynchronous threads access shared performance counter data simultaneously during FastRPC invocations.
Affected Software
2 affected components
Qualcomm FastRPC
Qualcomm DSP Service
Event History
Oct 6, 2026
CVE Published
via MITRE·06:30 AM
Data Sourced
via MITRE·06:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
Exploitation requires local access and low privileges. The attack vector is local, so it is not described as remotely exploitable over a network.
2
Does exploitation require user interaction?
No. The CVSS vector specifies no user interaction is required.
3
What is the potential impact of successful exploitation?
Successful exploitation may result in high impact to confidentiality, integrity, and availability.