Improper Validation of Array Index in Bluetooth HOST

CVE Details

Basic Information

Title Improper Validation of Array Index in Bluetooth HOST
Type cve
Published 2025-08-06T07:26:10.779Z
Modified 2025-08-06T07:26:10.779Z

Product Information

Vendor Qualcomm, Inc.
Product Snapdragon
Version AQT1000

CVSS Information

Base Score 7.8 (HIGH)
Attack Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

  • Qualcomm, Inc. Snapdragon AQT1000
  • Qualcomm, Inc. Snapdragon FastConnect 6200
  • Qualcomm, Inc. Snapdragon FastConnect 6700
  • Qualcomm, Inc. Snapdragon FastConnect 6800
  • Qualcomm, Inc. Snapdragon FastConnect 6900
  • Qualcomm, Inc. Snapdragon FastConnect 7800
  • Qualcomm, Inc. Snapdragon QCA6391
  • Qualcomm, Inc. Snapdragon QCA6420
  • Qualcomm, Inc. Snapdragon QCA6430
  • Qualcomm, Inc. Snapdragon QCM5430
  • Qualcomm, Inc. Snapdragon QCM6490
  • Qualcomm, Inc. Snapdragon QCS5430
  • Qualcomm, Inc. Snapdragon QCS6490
  • Qualcomm, Inc. Snapdragon Qualcomm Video Collaboration VC3 Platform
  • Qualcomm, Inc. Snapdragon SC8380XP
  • Qualcomm, Inc. Snapdragon Snapdragon 7c+ Gen 3 Compute
  • Qualcomm, Inc. Snapdragon Snapdragon 8c Compute Platform (SC8180X-AD) “Poipu Lite”
  • Qualcomm, Inc. Snapdragon Snapdragon 8cx Compute Platform (SC8180X-AA, AB)
  • Qualcomm, Inc. Snapdragon Snapdragon 8cx Gen 2 5G Compute Platform (SC8180X-AC, AF) “Poipu Pro”
  • Qualcomm, Inc. Snapdragon Snapdragon 8cx Gen 3 Compute Platform (SC8280XP-AB, BB)
  • Qualcomm, Inc. Snapdragon WCD9340
  • Qualcomm, Inc. Snapdragon WCD9341
  • Qualcomm, Inc. Snapdragon WCD9370
  • Qualcomm, Inc. Snapdragon WCD9375
  • Qualcomm, Inc. Snapdragon WCD9380
  • Qualcomm, Inc. Snapdragon WCD9385
  • Qualcomm, Inc. Snapdragon WSA8810
  • Qualcomm, Inc. Snapdragon WSA8815
  • Qualcomm, Inc. Snapdragon WSA8830
  • Qualcomm, Inc. Snapdragon WSA8835
  • Qualcomm, Inc. Snapdragon WSA8840
  • Qualcomm, Inc. Snapdragon WSA8845
  • Qualcomm, Inc. Snapdragon WSA8845H

Additional Information

CWE List CWE-129
Source qualcomm

Description

Memory corruption while processing IOCTL command with larger buffer in Bluetooth Host.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.