CVE-2026-25260

high
Published 2026-06-01 ยท Modified 2026-06-03
CVSS v3
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
7.8

Description

Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.

Predictions

Exploit likelihood
75%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Application impact

VendorProductVersionsFixed
qualcommcologne-
qualcommfastconnect_6700-
qualcommfastconnect_6900-
qualcommfastconnect_7800-
qualcommqcm5430-
qualcommqcm6490-
qualcommvideo_collaboration_vc3_platform-
qualcommsc8380xp-
qualcommsd865_5g-
qualcommsnapdragon_ar1_gen_1_platform-
qualcommsnapdragon_xr2_5g_platform-
qualcommsnapdragon_xr2\+_gen_1_platform-
qualcommsxr2230p-
qualcommsxr2250p-
qualcommwcd9370-
qualcommwcd9375-
qualcommwcd9378c-
qualcommwcd9380-
qualcommwcd9385-
qualcommwsa8810-
qualcommwsa8815-
qualcommwsa8830-
qualcommwsa8832-
qualcommwsa8835-
qualcommwsa8840-
qualcommwsa8845-
qualcommwsa8845h-
qualcommx2000077-
qualcommx2000086-
qualcommx2000090-
qualcommx2000092-
qualcommx2000094-
qualcommxg101002-
qualcommxg101032-
qualcommxg101039-

References

CWEs

CWE-367

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.