{"id":20753,"date":"2025-10-08T22:28:39","date_gmt":"2025-10-08T22:28:39","guid":{"rendered":"http:\/\/localhost\/?p=20753"},"modified":"2025-10-08T22:28:39","modified_gmt":"2025-10-08T22:28:39","slug":"incorrect-calculation-of-buffer-size-in-hlos","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=20753","title":{"rendered":"Incorrect Calculation of Buffer Size in HLOS_CVE-2025-27053"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;Memory corruption during PlayReady APP usecase while processing TA commands.&#8221;,&#8221;published&#8221;:&#8221;2025-10-09T03:18:00.779Z&#8221;,&#8221;modified&#8221;:&#8221;2025-10-09T03:18:00.779Z&#8221;,&#8221;type&#8221;:&#8221;cve&#8221;,&#8221;title&#8221;:&#8221;Incorrect Calculation of Buffer Size in HLOS&#8221;,&#8221;source&#8221;:&#8221;qualcomm&#8221;,&#8221;references&#8221;:&#8221;https:\/\/docs.qualcomm.com\/product\/publicresources\/securitybulletin\/october-2025-bulletin.html&#8221;,&#8221;id&#8221;:&#8221;CVE-2025-27053&#8243;,&#8221;bulletinFamily&#8221;:&#8221;&#8221;,&#8221;cwe&#8221;:[&#8220;CWE-131&#8243;],&#8221;cvelist&#8221;:null,&#8221;sourceData&#8221;:&#8221;Qualcomm, Inc. Snapdragon 315 5G IoT Modem\\nQualcomm, Inc. Snapdragon 9205 LTE Modem\\nQualcomm, Inc. Snapdragon 9206 LTE Modem\\nQualcomm, Inc. Snapdragon 9207 LTE Modem\\nQualcomm, Inc. Snapdragon APQ8017\\nQualcomm, Inc. Snapdragon APQ8037\\nQualcomm, Inc. Snapdragon APQ8064AU\\nQualcomm, Inc. Snapdragon AQT1000\\nQualcomm, Inc. Snapdragon AR8031\\nQualcomm, Inc. Snapdragon AR8035\\nQualcomm, Inc. Snapdragon C-V2X 9150\\nQualcomm, Inc. Snapdragon CSRA6620\\nQualcomm, Inc. Snapdragon CSRA6640\\nQualcomm, Inc. Snapdragon CSRB31024\\nQualcomm, Inc. Snapdragon FastConnect 6200\\nQualcomm, Inc. Snapdragon FastConnect 6700\\nQualcomm, Inc. Snapdragon FastConnect 6800\\nQualcomm, Inc. Snapdragon FastConnect 6900\\nQualcomm, Inc. Snapdragon FastConnect 7800\\nQualcomm, Inc. Snapdragon Flight RB5 5G Platform\\nQualcomm, Inc. Snapdragon Home Hub 100 Platform\\nQualcomm, Inc. Snapdragon MDM8207\\nQualcomm, Inc. Snapdragon MDM9205S\\nQualcomm, Inc. Snapdragon MDM9250\\nQualcomm, Inc. Snapdragon MDM9628\\nQualcomm, Inc. Snapdragon MDM9640\\nQualcomm, Inc. Snapdragon MDM9650\\nQualcomm, Inc. Snapdragon MSM8996AU\\nQualcomm, Inc. Snapdragon PM8937\\nQualcomm, Inc. Snapdragon QAM8255P\\nQualcomm, Inc. Snapdragon QAM8295P\\nQualcomm, Inc. Snapdragon QAM8620P\\nQualcomm, Inc. Snapdragon QAM8650P\\nQualcomm, Inc. Snapdragon QAM8775P\\nQualcomm, Inc. Snapdragon QAMSRV1H\\nQualcomm, Inc. Snapdragon QAMSRV1M\\nQualcomm, Inc. Snapdragon QCA4004\\nQualcomm, Inc. Snapdragon QCA6174A\\nQualcomm, Inc. Snapdragon QCA6234\\nQualcomm, Inc. Snapdragon QCA6310\\nQualcomm, Inc. Snapdragon QCA6320\\nQualcomm, Inc. Snapdragon QCA6335\\nQualcomm, Inc. Snapdragon QCA6391\\nQualcomm, Inc. Snapdragon QCA6420\\nQualcomm, Inc. Snapdragon QCA6421\\nQualcomm, Inc. Snapdragon QCA6426\\nQualcomm, Inc. Snapdragon QCA6430\\nQualcomm, Inc. Snapdragon QCA6431\\nQualcomm, Inc. Snapdragon QCA6436\\nQualcomm, Inc. Snapdragon QCA6564\\nQualcomm, Inc. Snapdragon QCA6564A\\nQualcomm, Inc. Snapdragon QCA6564AU\\nQualcomm, Inc. Snapdragon QCA6574\\nQualcomm, Inc. Snapdragon QCA6574A\\nQualcomm, Inc. Snapdragon QCA6574AU\\nQualcomm, Inc. Snapdragon QCA6584AU\\nQualcomm, Inc. Snapdragon QCA6595\\nQualcomm, Inc. Snapdragon QCA6595AU\\nQualcomm, Inc. Snapdragon QCA6678AQ\\nQualcomm, Inc. Snapdragon QCA6688AQ\\nQualcomm, Inc. Snapdragon QCA6696\\nQualcomm, Inc. Snapdragon QCA6698AQ\\nQualcomm, Inc. Snapdragon QCA6698AU\\nQualcomm, Inc. Snapdragon QCA6797AQ\\nQualcomm, Inc. Snapdragon QCA8081\\nQualcomm, Inc. Snapdragon QCA8337\\nQualcomm, Inc. Snapdragon QCA8386\\nQualcomm, Inc. Snapdragon QCA8695AU\\nQualcomm, Inc. Snapdragon QCA9367\\nQualcomm, Inc. Snapdragon QCA9377\\nQualcomm, Inc. Snapdragon QCA9379\\nQualcomm, Inc. Snapdragon QCC2072\\nQualcomm, Inc. Snapdragon QCC710\\nQualcomm, Inc. Snapdragon QCC711\\nQualcomm, Inc. Snapdragon QCF8001\\nQualcomm, Inc. Snapdragon QCM2150\\nQualcomm, Inc. Snapdragon QCM2290\\nQualcomm, Inc. Snapdragon QCM4290\\nQualcomm, Inc. Snapdragon QCM4325\\nQualcomm, Inc. Snapdragon QCM4490\\nQualcomm, Inc. Snapdragon QCM5430\\nQualcomm, Inc. Snapdragon QCM6125\\nQualcomm, Inc. Snapdragon QCM6490\\nQualcomm, Inc. Snapdragon QCM6690\\nQualcomm, Inc. Snapdragon QCM8550\\nQualcomm, Inc. Snapdragon QCN6024\\nQualcomm, Inc. Snapdragon QCN6224\\nQualcomm, Inc. Snapdragon QCN6274\\nQualcomm, Inc. Snapdragon QCN7606\\nQualcomm, Inc. Snapdragon QCN9011\\nQualcomm, Inc. Snapdragon QCN9012\\nQualcomm, Inc. Snapdragon QCN9024\\nQualcomm, Inc. Snapdragon QCN9074\\nQualcomm, Inc. Snapdragon QCN9274\\nQualcomm, Inc. Snapdragon QCS2290\\nQualcomm, Inc. Snapdragon QCS410\\nQualcomm, Inc. Snapdragon QCS4290\\nQualcomm, Inc. Snapdragon QCS4490\\nQualcomm, Inc. Snapdragon QCS5430\\nQualcomm, Inc. Snapdragon QCS610\\nQualcomm, Inc. Snapdragon QCS6125\\nQualcomm, Inc. Snapdragon QCS615\\nQualcomm, Inc. Snapdragon QCS6490\\nQualcomm, Inc. Snapdragon QCS6690\\nQualcomm, Inc. Snapdragon QCS7230\\nQualcomm, Inc. Snapdragon QCS8155\\nQualcomm, Inc. Snapdragon QCS8250\\nQualcomm, Inc. Snapdragon QCS8300\\nQualcomm, Inc. Snapdragon QCS8550\\nQualcomm, Inc. Snapdragon QCS9100\\nQualcomm, Inc. Snapdragon QDU1000\\nQualcomm, Inc. Snapdragon QDU1010\\nQualcomm, Inc. Snapdragon QDU1110\\nQualcomm, Inc. Snapdragon QDU1210\\nQualcomm, Inc. Snapdragon QDX1010\\nQualcomm, Inc. Snapdragon QDX1011\\nQualcomm, Inc. Snapdragon QEP8111\\nQualcomm, Inc. Snapdragon QFW7114\\nQualcomm, Inc. Snapdragon QFW7124\\nQualcomm, Inc. Snapdragon QMP1000\\nQualcomm, Inc. Snapdragon QRB5165M\\nQualcomm, Inc. Snapdragon QRB5165N\\nQualcomm, Inc. Snapdragon QRU1032\\nQualcomm, Inc. Snapdragon QRU1052\\nQualcomm, Inc. Snapdragon QRU1062\\nQualcomm, Inc. Snapdragon QSM8250\\nQualcomm, Inc. Snapdragon QSM8350\\nQualcomm, Inc. Snapdragon QTS110\\nQualcomm, Inc. Snapdragon Qualcomm 215 Mobile Platform\\nQualcomm, Inc. Snapdragon Qualcomm Video Collaboration VC1 Platform\\nQualcomm, Inc. Snapdragon Qualcomm Video Collaboration VC3 Platform\\nQualcomm, Inc. Snapdragon Qualcomm Video Collaboration VC5 Platform\\nQualcomm, Inc. Snapdragon Robotics RB2 Platform\\nQualcomm, Inc. Snapdragon Robotics RB3 Platform\\nQualcomm, Inc. Snapdragon Robotics RB5 Platform\\nQualcomm, Inc. Snapdragon SA2150P\\nQualcomm, Inc. Snapdragon SA4150P\\nQualcomm, Inc. Snapdragon SA4155P\\nQualcomm, Inc. Snapdragon SA6145P\\nQualcomm, Inc. Snapdragon SA6150P\\nQualcomm, Inc. Snapdragon SA6155\\nQualcomm, Inc. Snapdragon SA6155P\\nQualcomm, Inc. Snapdragon SA7255P\\nQualcomm, Inc. Snapdragon SA7775P\\nQualcomm, Inc. Snapdragon SA8145P\\nQualcomm, Inc. Snapdragon SA8150P\\nQualcomm, Inc. Snapdragon SA8155\\nQualcomm, Inc. Snapdragon SA8155P\\nQualcomm, Inc. Snapdragon SA8195P\\nQualcomm, Inc. Snapdragon SA8255P\\nQualcomm, Inc. Snapdragon SA8295P\\nQualcomm, Inc. Snapdragon SA8530P\\nQualcomm, Inc. Snapdragon SA8540P\\nQualcomm, Inc. Snapdragon SA8620P\\nQualcomm, Inc. Snapdragon SA8650P\\nQualcomm, Inc. Snapdragon SA8770P\\nQualcomm, Inc. Snapdragon SA8775P\\nQualcomm, Inc. Snapdragon SA9000P\\nQualcomm, Inc. Snapdragon SC8180X+SDX55\\nQualcomm, Inc. Snapdragon SC8380XP\\nQualcomm, Inc. Snapdragon SD 675\\nQualcomm, Inc. Snapdragon SD 8 Gen1 5G\\nQualcomm, Inc. Snapdragon SD626\\nQualcomm, Inc. Snapdragon SD670\\nQualcomm, Inc. Snapdragon SD675\\nQualcomm, Inc. Snapdragon SD730\\nQualcomm, Inc. Snapdragon SD820\\nQualcomm, Inc. Snapdragon SD821\\nQualcomm, Inc. Snapdragon SD855\\nQualcomm, Inc. Snapdragon SD865 5G\\nQualcomm, Inc. Snapdragon SD888\\nQualcomm, Inc. Snapdragon SDM429W\\nQualcomm, Inc. Snapdragon SDX55\\nQualcomm, Inc. Snapdragon SDX61\\nQualcomm, Inc. Snapdragon SDX82\\nQualcomm, Inc. Snapdragon SDX85\\nQualcomm, Inc. Snapdragon SG4150P\\nQualcomm, Inc. Snapdragon SG6150\\nQualcomm, Inc. Snapdragon SG6150P\\nQualcomm, Inc. Snapdragon SG8275P\\nQualcomm, Inc. Snapdragon SM4125\\nQualcomm, Inc. Snapdragon SM4635\\nQualcomm, Inc. Snapdragon SM6225P\\nQualcomm, Inc. Snapdragon SM6250\\nQualcomm, Inc. Snapdragon SM6250P\\nQualcomm, Inc. Snapdragon SM6370\\nQualcomm, Inc. Snapdragon SM6650\\nQualcomm, Inc. Snapdragon SM6650P\\nQualcomm, Inc. Snapdragon SM7250P\\nQualcomm, Inc. Snapdragon SM7315\\nQualcomm, Inc. Snapdragon SM7325P\\nQualcomm, Inc. Snapdragon SM7635\\nQualcomm, Inc. Snapdragon SM7635P\\nQualcomm, Inc. Snapdragon SM7675\\nQualcomm, Inc. Snapdragon SM7675P\\nQualcomm, Inc. Snapdragon SM8550P\\nQualcomm, Inc. Snapdragon SM8635\\nQualcomm, Inc. Snapdragon SM8635P\\nQualcomm, Inc. Snapdragon SM8650Q\\nQualcomm, Inc. Snapdragon SM8735\\nQualcomm, Inc. Snapdragon SM8750\\nQualcomm, Inc. Snapdragon SM8750P\\nQualcomm, Inc. Snapdragon SM8850\\nQualcomm, Inc. Snapdragon SM8850P\\nQualcomm, Inc. Snapdragon Smart Audio 400 Platform\\nQualcomm, Inc. Snapdragon Smart Display 200 Platform (APQ5053-AA)\\nQualcomm, Inc. Snapdragon Snapdragon 1100 Wearable Platform\\nQualcomm, Inc. Snapdragon Snapdragon 1200 Wearable Platform\\nQualcomm, Inc. Snapdragon Snapdragon 4 Gen 1 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 4 Gen 2 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 425 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 427 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 429 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 430 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 435 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 439 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 450 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 460 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 480 5G Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 480+ 5G Mobile Platform (SM4350-AC)\\nQualcomm, Inc. Snapdragon Snapdragon 625 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 626 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 632 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 662 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 665 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 670 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 675 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 678 Mobile Platform (SM6150-AC)\\nQualcomm, Inc. Snapdragon Snapdragon 680 4G Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 685 4G Mobile Platform (SM6225-AD)\\nQualcomm, Inc. Snapdragon Snapdragon 690 5G Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 695 5G Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 710 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 712 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 720G Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 730 Mobile Platform (SM7150-AA)\\nQualcomm, Inc. Snapdragon Snapdragon 730G Mobile Platform (SM7150-AB)\\nQualcomm, Inc. Snapdragon Snapdragon 732G Mobile Platform (SM7150-AC)\\nQualcomm, Inc. Snapdragon Snapdragon 750G 5G Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 765 5G Mobile Platform (SM7250-AA)\\nQualcomm, Inc. Snapdragon Snapdragon 765G 5G Mobile Platform (SM7250-AB)\\nQualcomm, Inc. Snapdragon Snapdragon 768G 5G Mobile Platform (SM7250-AC)\\nQualcomm, Inc. Snapdragon Snapdragon 778G 5G Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 778G+ 5G Mobile Platform (SM7325-AE)\\nQualcomm, Inc. Snapdragon Snapdragon 780G 5G Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 782G Mobile Platform (SM7325-AF)\\nQualcomm, Inc. Snapdragon Snapdragon 7c Compute Platform (SC7180-AC)\\nQualcomm, Inc. Snapdragon Snapdragon 7c Gen 2 Compute Platform (SC7180-AD) \\&#8221;Rennell Pro\\&#8221;\\nQualcomm, Inc. Snapdragon Snapdragon 7c+ Gen 3 Compute\\nQualcomm, Inc. Snapdragon Snapdragon 8 Gen 1 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 8 Gen 2 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 8 Gen 3 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 8+ Gen 1 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 8+ Gen 2 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 820 Automotive Platform\\nQualcomm, Inc. Snapdragon Snapdragon 820 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 821 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 845 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 855 Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 855+\/860 Mobile Platform (SM8150-AC)\\nQualcomm, Inc. Snapdragon Snapdragon 865 5G Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 865+ 5G Mobile Platform (SM8250-AB)\\nQualcomm, Inc. Snapdragon Snapdragon 870 5G Mobile Platform (SM8250-AC)\\nQualcomm, Inc. Snapdragon Snapdragon 888 5G Mobile Platform\\nQualcomm, Inc. Snapdragon Snapdragon 888+ 5G Mobile Platform (SM8350-AC)\\nQualcomm, Inc. Snapdragon Snapdragon 8c Compute Platform (SC8180X-AD) \\&#8221;Poipu Lite\\&#8221;\\nQualcomm, Inc. Snapdragon Snapdragon 8c Compute Platform (SC8180XP-AD) \\&#8221;Poipu Lite\\&#8221;\\nQualcomm, Inc. Snapdragon Snapdragon 8cx Compute Platform (SC8180X-AA, AB)\\nQualcomm, Inc. Snapdragon Snapdragon 8cx Compute Platform (SC8180XP-AC, AF) \\&#8221;Poipu Pro\\&#8221;\\nQualcomm, Inc. Snapdragon Snapdragon 8cx Gen 2 5G Compute Platform (SC8180X-AC, AF) \\&#8221;Poipu Pro\\&#8221;\\nQualcomm, Inc. Snapdragon Snapdragon 8cx Gen 2 5G Compute Platform (SC8180XP-AA, AB)\\nQualcomm, Inc. Snapdragon Snapdragon 8cx Gen 3 Compute Platform (SC8280XP-AB, BB)\\nQualcomm, Inc. Snapdragon Snapdragon AR1 Gen 1 Platform\\nQualcomm, Inc. Snapdragon Snapdragon AR1 Gen 1 Platform \\&#8221;Luna1\\&#8221;\\nQualcomm, Inc. Snapdragon Snapdragon AR2 Gen 1 Platform\\nQualcomm, Inc. Snapdragon Snapdragon Auto 5G Modem-RF\\nQualcomm, Inc. Snapdragon Snapdragon Auto 5G Modem-RF Gen 2\\nQualcomm, Inc. Snapdragon Snapdragon W5+ Gen 1 Wearable Platform\\nQualcomm, Inc. Snapdragon Snapdragon Wear 1300 Platform\\nQualcomm, Inc. Snapdragon Snapdragon Wear 4100+ Platform\\nQualcomm, Inc. Snapdragon Snapdragon X12 LTE Modem\\nQualcomm, Inc. Snapdragon Snapdragon X24 LTE Modem\\nQualcomm, Inc. Snapdragon Snapdragon X32 5G Modem-RF System\\nQualcomm, Inc. Snapdragon Snapdragon X35 5G Modem-RF System\\nQualcomm, Inc. Snapdragon Snapdragon X5 LTE Modem\\nQualcomm, Inc. Snapdragon Snapdragon X50 5G Modem-RF System\\nQualcomm, Inc. Snapdragon Snapdragon X55 5G Modem-RF System\\nQualcomm, Inc. Snapdragon Snapdragon X62 5G Modem-RF System\\nQualcomm, Inc. Snapdragon Snapdragon X65 5G Modem-RF System\\nQualcomm, Inc. Snapdragon Snapdragon X72 5G Modem-RF System\\nQualcomm, Inc. Snapdragon Snapdragon X75 5G Modem-RF System\\nQualcomm, Inc. Snapdragon Snapdragon XR1 Platform\\nQualcomm, Inc. Snapdragon Snapdragon XR2 5G Platform\\nQualcomm, Inc. Snapdragon Snapdragon XR2+ Gen 1 Platform\\nQualcomm, Inc. Snapdragon Snapdragon Auto 4G Modem\\nQualcomm, Inc. Snapdragon SRV1H\\nQualcomm, Inc. Snapdragon SRV1L\\nQualcomm, Inc. Snapdragon SRV1M\\nQualcomm, Inc. Snapdragon SSG2115P\\nQualcomm, Inc. Snapdragon SSG2125P\\nQualcomm, Inc. Snapdragon SW5100\\nQualcomm, Inc. Snapdragon SW5100P\\nQualcomm, Inc. Snapdragon SXR1120\\nQualcomm, Inc. Snapdragon SXR1230P\\nQualcomm, Inc. Snapdragon SXR2130\\nQualcomm, Inc. Snapdragon SXR2230P\\nQualcomm, Inc. Snapdragon SXR2250P\\nQualcomm, Inc. Snapdragon SXR2330P\\nQualcomm, Inc. Snapdragon SXR2350P\\nQualcomm, Inc. Snapdragon TalynPlus\\nQualcomm, Inc. Snapdragon Vision Intelligence 100 Platform (APQ8053-AA)\\nQualcomm, Inc. Snapdragon Vision Intelligence 200 Platform (APQ8053-AC)\\nQualcomm, Inc. Snapdragon Vision Intelligence 300 Platform\\nQualcomm, Inc. Snapdragon Vision Intelligence 400 Platform&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:7.8,&#8221;severity&#8221;:&#8221;HIGH&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:L\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;&#8221;,&#8221;category_name&#8221;:&#8221;CVE&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;Snapdragon&#8221;,&#8221;version&#8221;:&#8221;315 5G IoT Modem&#8221;,&#8221;vendor&#8221;:&#8221;Qualcomm, Inc.&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;Memory corruption during PlayReady APP usecase while processing TA commands.&#8221;,&#8221;published&#8221;:&#8221;2025-10-09T03:18:00.779Z&#8221;,&#8221;modified&#8221;:&#8221;2025-10-09T03:18:00.779Z&#8221;,&#8221;type&#8221;:&#8221;cve&#8221;,&#8221;title&#8221;:&#8221;Incorrect Calculation of Buffer Size in HLOS&#8221;,&#8221;source&#8221;:&#8221;qualcomm&#8221;,&#8221;references&#8221;:&#8221;https:\/\/docs.qualcomm.com\/product\/publicresources\/securitybulletin\/october-2025-bulletin.html&#8221;,&#8221;id&#8221;:&#8221;CVE-2025-27053&#8243;,&#8221;bulletinFamily&#8221;:&#8221;&#8221;,&#8221;cwe&#8221;:[&#8220;CWE-131&#8243;],&#8221;cvelist&#8221;:null,&#8221;sourceData&#8221;:&#8221;Qualcomm, Inc. Snapdragon 315 5G IoT Modem\\nQualcomm, Inc. Snapdragon 9205&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[6,8,28,12,15,13,7,11,5],"class_list":["post-20753","post","type-post","status-publish","format-standard","hentry","category-category_cve","tag-cve","tag-cvss","tag-cvss-78","tag-exploit","tag-high","tag-news","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Incorrect Calculation of Buffer Size in HLOS_CVE-2025-27053 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=20753\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Incorrect Calculation of Buffer Size in HLOS_CVE-2025-27053 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;Memory corruption during PlayReady APP usecase while processing TA commands.&#8221;,&#8221;published&#8221;:&#8221;2025-10-09T03:18:00.779Z&#8221;,&#8221;modified&#8221;:&#8221;2025-10-09T03:18:00.779Z&#8221;,&#8221;type&#8221;:&#8221;cve&#8221;,&#8221;title&#8221;:&#8221;Incorrect Calculation of Buffer Size in HLOS&#8221;,&#8221;source&#8221;:&#8221;qualcomm&#8221;,&#8221;references&#8221;:&#8221;https:\/\/docs.qualcomm.com\/product\/publicresources\/securitybulletin\/october-2025-bulletin.html&#8221;,&#8221;id&#8221;:&#8221;CVE-2025-27053&#8243;,&#8221;bulletinFamily&#8221;:&#8221;&#8221;,&#8221;cwe&#8221;:[&#8220;CWE-131&#8243;],&#8221;cvelist&#8221;:null,&#8221;sourceData&#8221;:&#8221;Qualcomm, Inc. Snapdragon 315 5G IoT ModemnQualcomm, Inc. Snapdragon 9205...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=20753\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-10-08T22:28:39+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20753#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20753\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Incorrect Calculation of Buffer Size in HLOS_CVE-2025-27053\",\"datePublished\":\"2025-10-08T22:28:39+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20753\"},\"wordCount\":1848,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-7.8\",\"exploit\",\"HIGH\",\"news\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_cve\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=20753#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20753\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20753\",\"name\":\"Incorrect Calculation of Buffer Size in HLOS_CVE-2025-27053 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-10-08T22:28:39+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20753#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=20753\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20753#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Incorrect Calculation of Buffer Size in HLOS_CVE-2025-27053\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Incorrect Calculation of Buffer Size in HLOS_CVE-2025-27053 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=20753","og_locale":"en_US","og_type":"article","og_title":"Incorrect Calculation of Buffer Size in HLOS_CVE-2025-27053 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;Memory corruption during PlayReady APP usecase while processing TA commands.&#8221;,&#8221;published&#8221;:&#8221;2025-10-09T03:18:00.779Z&#8221;,&#8221;modified&#8221;:&#8221;2025-10-09T03:18:00.779Z&#8221;,&#8221;type&#8221;:&#8221;cve&#8221;,&#8221;title&#8221;:&#8221;Incorrect Calculation of Buffer Size in HLOS&#8221;,&#8221;source&#8221;:&#8221;qualcomm&#8221;,&#8221;references&#8221;:&#8221;https:\/\/docs.qualcomm.com\/product\/publicresources\/securitybulletin\/october-2025-bulletin.html&#8221;,&#8221;id&#8221;:&#8221;CVE-2025-27053&#8243;,&#8221;bulletinFamily&#8221;:&#8221;&#8221;,&#8221;cwe&#8221;:[&#8220;CWE-131&#8243;],&#8221;cvelist&#8221;:null,&#8221;sourceData&#8221;:&#8221;Qualcomm, Inc. Snapdragon 315 5G IoT ModemnQualcomm, Inc. Snapdragon 9205...","og_url":"https:\/\/zero.redgem.net\/?p=20753","og_site_name":"zero redgem","article_published_time":"2025-10-08T22:28:39+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=20753#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=20753"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Incorrect Calculation of Buffer Size in HLOS_CVE-2025-27053","datePublished":"2025-10-08T22:28:39+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=20753"},"wordCount":1848,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-7.8","exploit","HIGH","news","Security","tapic","Vulnerability"],"articleSection":["category_cve"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=20753#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=20753","url":"https:\/\/zero.redgem.net\/?p=20753","name":"Incorrect Calculation of Buffer Size in HLOS_CVE-2025-27053 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-10-08T22:28:39+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=20753#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=20753"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=20753#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Incorrect Calculation of Buffer Size in HLOS_CVE-2025-27053"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/20753","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=20753"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/20753\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=20753"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=20753"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=20753"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}