CVE-2025-27074Incorrect Calculation of Buffer Size in INC Snapdragon

Severity
7.8HIGHNVD
OSV5.5
EPSS
0.0%
top 96.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 4
Latest updateDec 1

Description

Memory corruption while processing a GP command response.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages7 packages

Ubuntulinux/linux_kernel< 4.4.0-272.306+1
CVEListV5qualcomm_inc/snapdragon95 versions+94

🔴Vulnerability Details

7
GHSA
GHSA-qxjh-59hj-xh63: Memory corruption while processing a GP command response2025-11-04
OSV
linux-aws-fips vulnerabilities2025-09-24
OSV
linux-fips, linux-azure-fips, linux-gcp-fips vulnerabilities2025-09-17
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities2025-09-17
OSV
linux-aws vulnerabilities2025-09-02

📋Vendor Advisories

2
Android
CVE-2025-27074: Closed-source component2025-12-01
Microsoft
media: go7007: fix a memleak in go7007_load_encoder2024-05-14
CVE-2025-27074 — Incorrect Calculation of Buffer Size | cvebase