CVE-2025-21483Improper Restriction of Operations within the Bounds of a Memory Buffer in INC Snapdragon

Severity
9.8CRITICALNVD
EPSS
0.1%
top 83.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 24

Description

Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5qualcomm_inc/snapdragon227 versions+226

🔴Vulnerability Details

1
GHSA
GHSA-jg77-qwrp-9pph: Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs2025-09-24

📋Vendor Advisories

1
Android
CVE-2025-21483: Closed-source component2025-09-01