CVE-2026-25281
massTransient Denial-of-Service in Qualcomm Component via Unvalidated Request Buffers
CVE-2026-25281 is a resource-allocation flaw (CWE-770) in a Qualcomm component that processes request buffers, where incoming large or numerous buffers are accepted without sufficient memory-allocation validation. An unprivileged attacker with adjacent-network access (CVSS AV:A, e.g., on the same LAN or within Wi-Fi/Wireless proximity) can trigger excessive memory consumption, causing a transient denial of service; availability impact is rated high (A:H) with no confidentiality or integrity impact. Because the scope is changed (S:C), the exhaustion affects resources beyond the vulnerable component's own security scope, such as a shared subsystem crashing or hanging, with the condition typically recovering after restart. Devices running the affected Qualcomm component are exposed, although the source data does not enumerate the specific chipsets or versions, so defenders should consult Qualcomm's security bulletin for the definitive affected-product list. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.
What to do: Watch the Qualcomm security bulletin assigned by [email protected] for the definitive list of affected chipsets, then apply the corresponding OEM/device firmware update as soon as it is offered. Until patched, reduce adjacent-network exposure for likely affected Qualcomm-based devices (restrict access to shared LANs and Wi-Fi, and review which unauthenticated clients can reach them). Check with your device vendor for updates addressing CVE-2026-25281, since Qualcomm fixes of this type typically ship through OEM builds rather than as standalone patches.
| Qualcomm component processing request buffers (specific chipset/component not enumerated in the available data) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.
- Weakness
- CWE-770
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.