CVE-2025-21476Classic Buffer Overflow in INC Snapdragon

Severity
7.8HIGHNVD
EPSS
0.0%
top 95.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 24

Description

Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

CVEListV5qualcomm_inc/snapdragon42 versions+41

🔴Vulnerability Details

1
GHSA
GHSA-m9g8-x7f2-2hgc: Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake2025-09-24