PatchSiren cyber security CVE debrief
CVE-2026-25278 Qualcomm, Inc. CVE debrief
A memory corruption vulnerability exists when processing I2C transfer requests due to a race condition between memory allocation and data copying. This issue has a CVSS score of 7.8 and is classified as HIGH severity. The CVE record was published on 2026-09-17T05:17:00.847Z and was last modified on 2026-09-18T19:06:08.407Z. The vulnerability affects Qualcomm products and could allow for arbitrary code execution or other malicious activities if exploited. Defenders should prioritize verifying affected systems, assessing exposure, and applying patches or mitigations as available.
- Vendor
- Qualcomm, Inc.
- Product
- Snapdragon
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-17
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-17
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for systems using affected Qualcomm products should assess exposure and prioritize patching or mitigation efforts. This includes verifying affected systems, assessing potential impact, and applying patches or mitigations as available. Additionally, defenders should review and monitor system logs for suspicious activity and consider implementing compensating controls for exposed systems while
Why it matters
This HIGH-severity memory corruption vulnerability exists when processing I2C transfer requests due to a race condition between memory allocation and data copying. Defenders should prioritize verifying affected systems, assessing exposure, and applying patches or mitigations as available. Additional information on affected versions and remediation is needed.
- Verify system exposure and assess potential impact
- Apply patches or mitigations as available
- Monitor system logs for suspicious activity
Technical summary
The vulnerability exists due to a race condition between memory allocation and data copying when processing I2C transfer requests. This can lead to memory corruption and potentially allow for arbitrary code execution or other malicious activities. The vulnerability affects Qualcomm products and has a CVSS score of 7.8, classified as HIGH severity. The CVE record was published on 2026-09-17T05:17:00.847Z and was last modified on 2026-09-18T19:06:08.407Z.
Defensive priority
Defenders should prioritize verifying affected systems, assessing exposure, and applying patches or mitigations as available.
Recommended defensive actions
- Verify system exposure and assess potential impact
- Review and apply patches or mitigations as available
- Monitor system logs for suspicious activity
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but additional information on affected versions and remediation is needed. The vulnerability is caused by a race condition between memory allocation and data copying when processing I2C transfer requests. This can lead to memory corruption and potentially allow for arbitrary code execution or other malicious activities. The CVE record was published on 2026-09-17T05:17:00.847Z and has not been modified since then. The N2
Sources and references
Verified primary and authoritative sources
-
CVE-2026-25278 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-25278
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-25278 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-25278
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://docs.qualcomm.com/product/publicresources/securitybulletin/september-2026-bulletin.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.