CVE-2026-25271 Details
Description
Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.
A vulnerability has been identified in Qualcomm's Digital Signal Processor (DSP) service, allowing for a time-of-check time-of-use (TOCTOU) race condition. This vulnerability leads to memory corruption when processing asynchronous input parameters, due to improper handling of modified values between the check and use phases. The issue affects several chipsets within Qualcomm's product range.
Qualcomm has notified device manufacturers about this vulnerability and is actively sharing patches. For information on the patching status of released devices, contact the device manufacturer.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.qualcomm.com/product/publicresources/securitybulletin/july-2026-bulletin.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| qualcomm cologne firmware | All versions |
CPE
Remediation
| |
| qualcomm cologne | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 6900 firmware | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 6900 | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 7800 firmware | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 7800 | All versions |
CPE
Remediation
| |
| qualcomm iqx5121 firmware | All versions |
CPE
Remediation
| |
| qualcomm iqx5121 | All versions |
CPE
Remediation
| |
| qualcomm iqx7181 firmware | All versions |
CPE
Remediation
| |
| qualcomm iqx7181 | All versions |
CPE
Remediation
| |
| qualcomm qca0000 firmware | All versions |
CPE
Remediation
| |
| qualcomm qca0000 | All versions |
CPE
Remediation
| |
| qualcomm sc8380xp firmware | All versions |
CPE
Remediation
| |
| qualcomm sc8380xp | All versions |
CPE
Remediation
| |
| qualcomm wcd9378c firmware | All versions |
CPE
Remediation
| |
| qualcomm wcd9378c | All versions |
CPE
Remediation
| |
| qualcomm wcd9380 firmware | All versions |
CPE
Remediation
| |
| qualcomm wcd9380 | All versions |
CPE
Remediation
| |
| qualcomm wcd9385 firmware | All versions |
CPE
Remediation
| |
| qualcomm wcd9385 | All versions |
CPE
Remediation
| |
| qualcomm wsa8840 firmware | All versions |
CPE
Remediation
| |
| qualcomm wsa8840 | All versions |
CPE
Remediation
| |
| qualcomm wsa8845 firmware | All versions |
CPE
Remediation
| |
| qualcomm wsa8845 | All versions |
CPE
Remediation
| |
| qualcomm wsa8845h firmware | All versions |
CPE
Remediation
| |
| qualcomm wsa8845h | All versions |
CPE
Remediation
| |
| qualcomm x2000077 firmware | All versions |
CPE
Remediation
| |
| qualcomm x2000077 | All versions |
CPE
Remediation
| |
| qualcomm x2000086 firmware | All versions |
CPE
Remediation
| |
| qualcomm x2000086 | All versions |
CPE
Remediation
| |
| qualcomm x2000090 firmware | All versions |
CPE
Remediation
| |
| qualcomm x2000090 | All versions |
CPE
Remediation
| |
| qualcomm x2000092 firmware | All versions |
CPE
Remediation
| |
| qualcomm x2000092 | All versions |
CPE
Remediation
| |
| qualcomm x2000094 firmware | All versions |
CPE
Remediation
| |
| qualcomm x2000094 | All versions |
CPE
Remediation
| |
| qualcomm xg101002 firmware | All versions |
CPE
Remediation
| |
| qualcomm xg101002 | All versions |
CPE
Remediation
| |
| qualcomm xg101032 firmware | All versions |
CPE
Remediation
| |
| qualcomm xg101032 | All versions |
CPE
Remediation
| |
| qualcomm xg101039 firmware | All versions |
CPE
Remediation
| |
| qualcomm xg101039 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 7, 2026 | Initial Analysis | [email protected] |
| Jul 7, 2026 | CVE Modified | CISA-ADP |
| Jul 6, 2026 | New CVE Received | [email protected] |
| Jul 6, 2026 | CVE Modified | CISA-ADP |