CVE-2025-27058 Details
Description
Memory corruption while processing packet data with exceedingly large packet.
A memory corruption vulnerability has been identified in various chipsets of Qualcomm products, including those in the Snapdragon 8 and 7 series, as well as in several platforms such as Windows WLAN Host and core services. This vulnerability arises from improper validation of packet data, particularly when processing exceedingly large packets, which can lead to classic buffer overflow scenarios. The issue can be exploited locally, causing memory corruption that could potentially be leveraged for arbitrary code execution.
Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm July 2025 Security Bulletin.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2025-bulletin.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| qualcomm fastconnect 6900 firmware | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 6900 | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 7800 firmware | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 7800 | All versions |
CPE
Remediation
| |
| qualcomm sc8380xp firmware | All versions |
CPE
Remediation
| |
| qualcomm sc8380xp | All versions |
CPE
Remediation
| |
| qualcomm wcd9380 firmware | All versions |
CPE
Remediation
| |
| qualcomm wcd9380 | All versions |
CPE
Remediation
| |
| qualcomm wcd9385 firmware | All versions |
CPE
Remediation
| |
| qualcomm wcd9385 | All versions |
CPE
Remediation
| |
| qualcomm wsa8840 firmware | All versions |
CPE
Remediation
| |
| qualcomm wsa8840 | All versions |
CPE
Remediation
| |
| qualcomm wsa8845 firmware | All versions |
CPE
Remediation
| |
| qualcomm wsa8845 | All versions |
CPE
Remediation
| |
| qualcomm wsa8845h firmware | All versions |
CPE
Remediation
| |
| qualcomm wsa8845h | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2025 | Initial Analysis | [email protected] |
| Jul 8, 2025 | New CVE Received | [email protected] |