PT-2025-48445 · Qualcomm · Snapdragon 8 Gen 3+1

Published

2025-09-01

·

Updated

2026-01-05

·

CVE-2025-47372

CVSS v3.1

9.0

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Qualcomm Snapdragon (affected versions not specified)
Description A flaw exists in Qualcomm Snapdragon chipsets related to insufficient input validation during buffer copying. Specifically, a corrupted ELF image with an oversized file size can be read into a buffer without proper authentication, leading to potential memory corruption. This issue impacts components such as HLOS, TZ Firmware, DSP, audio, and camera. The vulnerability compromises the boot process and poses a local privilege escalation risk. Millions of devices may be affected. The issue involves a buffer copy operation without checking the size of the input data. The vulnerability is present in the secure boot process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-15426
CVE-2025-47372

Affected Products

5G Modem
Snapdragon 8 Gen 3