CVE-2026-25277

high
Published 2026-06-01 ยท Modified 2026-06-03
CVSS v3
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
8.8

Description

Memory corruption while using Strongbox due to buffer overflow.

Predictions

Exploit likelihood
82%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Application impact

VendorProductVersionsFixed
qualcommcq8750m-
qualcommfastconnect_6700-
qualcommfastconnect_6800-
qualcommfastconnect_6900-
qualcommfastconnect_7800-
qualcommg3x_gen_2-
qualcommpandeiro-
qualcommqca6391-
qualcommqca6698au-
qualcommqca6797aq-
qualcommqcm5430-
qualcommqcm6490-
qualcommqcm8838-
qualcommqcn9011-
qualcommqcn9012-
qualcommqcs8550-
qualcommvideo_collaboration_vc3_platform-
qualcommsd865_5g-
qualcommsdr753-
qualcommsm8550p-
qualcommsm8650q-
qualcommsm8750p-
qualcommsnapdragon_460_mobile_platform-
qualcommsnapdragon_662_mobile_platform-
qualcommsnapdragon_8_elite-
qualcommsnapdragon_8_elite_gen_5-
qualcommsnapdragon_8_gen_2_mobile_platform-
qualcommsnapdragon_8_gen_3_mobile_platform-
qualcommsnapdragon_8\+_gen_2_mobile_platform-
qualcommsnapdragon_865_5g_mobile_platform-
qualcommsnapdragon_865\+_5g_mobile_platform-
qualcommsnapdragon_870_5g_mobile_platform-
qualcommsnapdragon_ar1_gen_1_platform-
qualcommsnapdragon_x55_5g_modem-rf_system-
qualcommsnapdragon_xr2_5g_platform-
qualcommsnapdragon_xr2\+_gen_1_platform-
qualcommwcd9370-
qualcommwcd9375-
qualcommwcd9380-
qualcommwcd9385-
qualcommwcd9390-
qualcommwcd9395-
qualcommwcn3950-
qualcommwcn3988-
qualcommwcn7760-
qualcommwcn7860-
qualcommwcn7861-
qualcommwcn7880-
qualcommwcn7881-
qualcommwsa8810-
qualcommwsa8815-
qualcommwsa8830-
qualcommwsa8832-
qualcommwsa8835-
qualcommwsa8840-
qualcommwsa8845-
qualcommwsa8845h-

References

CWEs

CWE-120

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.