PatchSiren cyber security CVE debrief
CVE-2026-25281 Qualcomm, Inc. CVE debrief
A transient denial-of-service (DoS) vulnerability exists in Qualcomm products when processing large or numerous request buffers without sufficient memory allocation validation. This issue, classified as HIGH severity with a CVSS score of 7.4, can lead to potential disruption of service. The vulnerability's scope and affected products are not fully detailed in the CVE record or NVD entry, necessitating further verification and assessment by defenders. Evidence is limited, and additional review is required to determine the full impact and to prioritize patching from Qualcomm.
- Vendor
- Qualcomm, Inc.
- Product
- Snapdragon
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-17
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-17
- Advisory updated
- 2026-09-18
Who should care
Defenders, security teams, and IT personnel responsible for maintaining and securing systems that utilize Qualcomm products should assess exposure and prioritize patching.
Why it matters
CVE-2026-25281 is a transient DoS vulnerability with a CVSS score of 7.4, requiring defenders to assess exposure, prioritize patching from Qualcomm, and implement compensating controls. Evidence is limited, and further verification is needed to determine the full scope of affected products and versions.
- Potential disruption of service due to transient DoS
- Need for verification of patch availability and application
- Potential impact on system availability and reliability
Technical summary
The vulnerability exists due to insufficient memory allocation validation when processing large or numerous request buffers in Qualcomm products, leading to a transient denial-of-service (DoS). This issue has a CVSS score of 7.4 and is classified as HIGH severity. The CVE record and NVD entry provide limited information about the vulnerability, particularly regarding affected products and versions. Defenders should focus on verifying and applying patches from Qualcomm, assessing exposure in their environments, and implementing compensating controls to mitigate the
Defensive priority
Defenders should prioritize verifying and applying patches from Qualcomm, assessing exposure in their environments, and implementing compensating controls to mitigate potential impacts.
Recommended defensive actions
- Verify and apply patches from Qualcomm
- Assess exposure in environments
- Implement compensating controls
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further verification is required to determine the full scope of affected products and versions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-25281 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-25281
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-25281 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-25281
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://docs.qualcomm.com/product/publicresources/securitybulletin/september-2026-bulletin.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.