CVE-2026-25294
massBuffer over-read in Qualcomm WLAN frame parsing causes transient denial of service
CVE-2026-25294 is a buffer over-read (CWE-126) in a Qualcomm WLAN component that occurs while parsing a frame during channel usage. An attacker positioned in adjacent radio range (e.g., a nearby Wi-Fi peer) can send a specially crafted frame that triggers the over-read with no privileges or user interaction required. The result is high availability impact only: a transient denial of service of the wireless component, with no confidentiality or integrity loss and no evidence of code execution. Devices containing the affected Qualcomm WLAN component are exposed; the source data does not identify specific chipsets or firmware versions. Exploitation status is currently clean: the flaw is not in CISA KEV and no public proof-of-concept is known.
What to do: No fixed versions are listed in the source data; check Qualcomm's product security bulletin and your device OEM's/Android security bulletin for the fix mapped to CVE-2026-25294 and apply firmware updates when released. Because the attack vector is adjacent (nearby radio range), risk concentrates on Wi-Fi clients and access points within attacker proximity; the DoS is transient, so repeated exposure rather than a single frame is the practical concern. Monitor Qualcomm advisories for the affected chipset identifiers to confirm whether your fleet is in scope.
| Qualcomm | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Transient DOS while parsing frame during channel usage.
- Weakness
- CWE-126
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.