CVE-2026-25292
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.6
- CVSS vector
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.10%
- CWE
- CWE-1286
- Published
- 2026-08-04
- Last modified
- 2026-08-04
Affected products
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
- Qualcomm, Inc. Snapdragon
Weakness type
Related vulnerabilities
- CVE-2026-88009 — Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
- CVE-2026-83611 — xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content
- CVE-2026-72916 — Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses
- CVE-2026-0931 — Denial-of-service vulnerability in M-Files Server
- CVE-2026-57026 — Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash
- CVE-2026-55767 — Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle
- CVE-2026-50131 — Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
- CVE-2025-8873 — Arista EOS Dataplane Denial of Service via Malformed IPsec Packet