PT-2025-23468 · Qualcomm · Qualcomm Snapdragon
Published
2025-01-24
·
Updated
2025-08-06
·
CVE-2025-21479
CVSS v3.1
8.6
8.6
High
Base vector | Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Qualcomm Snapdragon GPU (affected versions not specified)
Description:
The issue is related to memory corruption due to unauthorized command execution in the GPU micronode while executing a specific sequence of commands. This is caused by insufficient authorization mechanisms in the GPU microcode. The vulnerability can be exploited by sending a sequence of specially crafted commands, potentially allowing an attacker to cause memory damage.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Authorization
Weakness Enumeration
Related Identifiers
BDU:2025-06374
CVE-2025-21479
Affected Products
Qualcomm Snapdragon
References · 46
- https://nvd.nist.gov/vuln/detail/CVE-2025-21479 · Security Note
- https://bdu.fstec.ru/vul/2025-06374 · Security Note
- https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html · Vendor Advisory
- https://twitter.com/macdonaldncode/status/1930066197455810957 · Twitter Post
- https://reddit.com/r/Action1/comments/1l859nk/todays_patch_tuesday_overview_66_vulnerabilities · Reddit Post
- https://twitter.com/cybrhoodsentinl/status/1929600489819120042 · Twitter Post
- https://twitter.com/SecAideInfo/status/1930569564191867115 · Twitter Post
- https://twitter.com/TweetThreatNews/status/1952793931168588232 · Twitter Post
- https://twitter.com/transilienceai/status/1930432886357803298 · Twitter Post
- https://t.me/ckure/15699 · Telegram Post
- https://t.me/latest_high_impact_cve/2527 · Telegram Post
- https://twitter.com/CVEnew/status/1929799360373805547 · Twitter Post
- https://twitter.com/BaseFortify/status/1929886672948216122 · Twitter Post
- https://reddit.com/r/CVEWatch/comments/1l68nfr/top_10_trending_cves_08062025 · Reddit Post
- https://twitter.com/techpio_team/status/1952995603094360067 · Twitter Post