CRITICAL🇵🇱 Wersja polska

CVE-2025-47372

CVSS 9.0v3.1pub. 2025-12-18upd. 2025-12-23

Memory Corruption when a corrupted ELF image with an oversized file size is read into a buffer without authentication.

🤖 AI Analysis
How it works

An attacker provides a specially crafted ELF image in which the file size field is artificially inflated. During loading of such an image into a buffer (without authentication or input validation), memory areas are overwritten that exceed the allocated buffer — which corresponds to error classes CWE-120 (classic buffer overflow) and CWE-787 (out-of-bounds write). The local vector (AV:L) and lack of privilege requirements (PR:N) and user interaction (UI:N) indicate that the flaw can be triggered by a locally accessible, unauthenticated process or low-level component.

Impact

An attacker can obtain full confidentiality and integrity of data beyond the component boundaries (S:C, C:H, I:H), which in practice means the possibility of executing arbitrary code or causing permanent damage to data in protected memory areas of the system.

Mitigation & patch

Patches available from the manufacturer should be applied according to references — detailed information and corrected firmware versions were published in the Qualcomm security bulletin from December 2025: https://docs.qualcomm.com/product/publicresources/securitybulletin/december-2025-bulletin.html

Who is affected

Hardware and firmware software: Qualcomm SA8650P, Qualcomm QAM8775P, Qualcomm QAM8650P, Qualcomm QCA6698AQ Firmware, Qualcomm QCA6797AQ Firmware — specific versions indicated in manufacturer references.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
  • Qualcomm Qam8255p

    HW
    Qualcomm
    all versions
  • Qualcomm Qam8255p Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Qam8620p

    HW
    Qualcomm
    all versions
  • Qualcomm Qam8620p Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Qam8650p

    HW
    Qualcomm
    all versions
  • Qualcomm Qam8650p Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Qam8775p

    HW
    Qualcomm
    all versions
  • Qualcomm Qam8775p Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Qamsrv1h

    HW
    Qualcomm
    all versions
  • Qualcomm Qamsrv1h Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Qamsrv1m

    HW
    Qualcomm
    all versions
  • Qualcomm Qamsrv1m Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Qca6595

    HW
    Qualcomm
    all versions
  • Qualcomm Qca6595au

    HW
    Qualcomm
    all versions
  • Qualcomm Qca6595au Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Qca6595 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Qca6678aq

    HW
    Qualcomm
    all versions
  • Qualcomm Qca6678aq Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Qca6696

    HW
    Qualcomm
    all versions
  • Qualcomm Qca6696 Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Qca6698aq

    HW
    Qualcomm
    all versions
  • Qualcomm Qca6698aq Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Qca6797aq

    HW
    Qualcomm
    all versions
  • Qualcomm Qca6797aq Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Sa7255p

    HW
    Qualcomm
    all versions
  • Qualcomm Sa7255p Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Sa7775p

    HW
    Qualcomm
    all versions
  • Qualcomm Sa7775p Firmware

    OS
    Qualcomm
    all versions
  • Qualcomm Sa8255p

    HW
    Qualcomm
    all versions
  • Qualcomm Sa8255p Firmware

    OS
    Qualcomm
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-25289CRITICAL9.6PL ✓same product

Przepełnienie bufora stosu w NAN Service Discovery Frames — Qualcomm

CVE-2025-21483CRITICAL9.8PL ✓same product

Memory corruption w Qualcomm podczas składania pakietów RTP (NALUs)

CVE-2025-27034CRITICAL9.8PL ✓same product

Qualcomm Firmware — memory corruption przy wyborze PLMN z listy SOR

CVE-2025-21450CRITICAL9.1PL ✓same product

Qualcomm: podatność kryptograficzna umożliwiająca Auth Bypass podczas pobierania

CVE-2024-45569CRITICAL9.8PL ✓same product

Qualcomm: Uszkodzenie pamięci przy parsowaniu ML IE w firmware