QualcommCVE-2026-25289
Qualcomm Snapdragon: memory corruption
Critical9.6CVE-2026-25289 · Published Aug 4, 2026 · updated Aug 6, 2026
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Snapdragon Product | <= AR8035 | No fix yet |
| <= Cologne | No fix yet | |
| <= CQ7790 | No fix yet | |
| <= CQ8725S | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-121
More Qualcomm advisories
All Qualcomm| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 4 | Qualcomm Snapdragon: memory corruption | High7.6 | No fix yet |
| Aug 4 | Qualcomm Snapdragon: memory corruption | High7.8 | No fix yet |
| Aug 4 | Weak configuration when UE does not verify the consistency of its additional... | High7.5 | No fix yet |
| Aug 4 | Transient DOS when processing a short target wake time channel usage response... | High7.4 | No fix yet |
| Aug 4 | Qualcomm Snapdragon: information disclosure | Medium6.5 | No fix yet |
| Aug 4 | Qualcomm Snapdragon: information disclosure | Medium6.5 | No fix yet |