CVE-2025-27031
HIGHCVSS 7.8/10EPSS 0.08%
Last modified
CVE-2025-27031 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. memory corruption while processing IOCTL commands, when the buffer in write loopback mode is accessed after being freed.. EPSS estimates a 0.08% chance of exploitation in the next 30 days.
Description
memory corruption while processing IOCTL commands, when the buffer in write loopback mode is accessed after being freed.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Fastconnect 6700 Firmware | All versions |
| Qualcomm | Fastconnect 6900 Firmware | All versions |
| Qualcomm | Fastconnect 7800 Firmware | All versions |
| Qualcomm | Qcm5430 Firmware | All versions |
| Qualcomm | Qcm6490 Firmware | All versions |
| Qualcomm | Qcs5430 Firmware | All versions |
| Qualcomm | Qcs6490 Firmware | All versions |
| Qualcomm | Video Collaboration Vc3 Platform Firmware | All versions |
| Qualcomm | Sc8380xp Firmware | All versions |
| Qualcomm | Snapdragon 7c\+ Gen 3 Compute Firmware | All versions |
| Qualcomm | Snapdragon 8cx Gen 3 Compute Platform \(Sc8280xp-Ab\) Firmware | All versions |
| Qualcomm | Snapdragon 8cx Gen 3 Compute Platform \(Sc8280xp-Bb\) Firmware | All versions |
| Qualcomm | Wcd9370 Firmware | All versions |
| Qualcomm | Wcd9375 Firmware | All versions |
| Qualcomm | Wcd9380 Firmware | All versions |
| Qualcomm | Wcd9385 Firmware | All versions |
| Qualcomm | Wsa8830 Firmware | All versions |
| Qualcomm | Wsa8835 Firmware | All versions |
| Qualcomm | Wsa8840 Firmware | All versions |
| Qualcomm | Wsa8845 Firmware | All versions |
| Qualcomm | Wsa8845h Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-27031?
memory corruption while processing IOCTL commands, when the buffer in write loopback mode is accessed after being freed.
How severe is CVE-2025-27031?
CVE-2025-27031 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.08% probability of exploitation in the next 30 days.
How do I fix CVE-2025-27031?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-27026A missing double-check feature in the WebGUI for CLI deactiv…4.9
- CVE-2025-27027A user with vpuser credentials that opens an SSH connection …4.1
- CVE-2025-27028The Linux deprivileged user vpuser in Radiflow iSAP Smart Co…6.8
- CVE-2025-27029Transient DOS while processing the tone measurement response…7.5
- CVE-2025-2703The built-in XY Chart plugin is vulnerable to a DOM XSS vuln…6.8
- CVE-2025-27030information disclosure while invoking calibration data from …6.1
- CVE-2025-27032memory corruption while loading a PIL authenticated VM, when…7.8
- CVE-2025-27033Information disclosure while running video usecase having ro…6.1
- CVE-2025-27034Memory corruption while selecting the PLMN from SOR failed l…9.8
- CVE-2025-27036Information disclosure when Video engine escape input data i…6.1
- CVE-2025-27037Memory corruption while processing config_dev IOCTL when cam…7.8
- CVE-2025-27038Memory corruption while rendering graphics using Adreno GPU …7.5
Are you affected by CVE-2025-27031?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
