#VU123411 Buffer over-read in Qualcomm products - CVE-2025-59600

 

#VU123411 Buffer over-read in Qualcomm products - CVE-2025-59600

Published: March 2, 2026


Vulnerability identifier: #VU123411
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-59600
CWE-ID: CWE-126
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
AR8031
AR8035
CSRA6620
CSRA6640
FastConnect 6200
FastConnect 6700
FastConnect 6900
FastConnect 7800
G1 Gen 1
G2 Gen 1
IQ6 Series Platform
IQ8 Series Platform
IQ9 Series Platform
LeMans_AU_LGIT
LeMansAU
MDM9628
Milos
Monaco_IOT
Netrani
Orne
Palawan25
Pandeiro
QAM8255P
QAMSRV1H
QAMSRV1M
QCA2066
QCA6391
QCA6564A
QCA6564AU
QCA6574
QCA6574A
QCA6595
QCA6595AU
QCA6688AQ
QCA6696
QCA6698AQ
QCA8081
QCA8337
QCM2290
QCM4325
QCM4490
QCM5430
QCM6125
QCM6490
QCN6024
QCN9011
QCN9012
QCN9024
QCS2290
QCS4290
QCS4490
QCS8550
QLN1083BD
QLN1086BD
QMP1000
QPA1083BD
QPA1086BD
Qualcomm Video Collaboration VC1 Platform
Qualcomm Video Collaboration VC3 Platform
Qualcomm Video Collaboration VC5 Platform
QXM1083
QXM1086
QXM1093
QXM1094
QXM1095
QXM1096
SA4150P
SA4155P
SA6145P
SA6150P
SA7255P
SA7775P
SA8145P
SA8150P
SA8155P
SA8195P
SA8255P
SA8770P
SAR1165P
SAR1250P
SAR2130P
SAR2230P
SC8380XP
SD662
SD865 5G
SDX61
SM6225P
SM6650P
SM7435
SM7635P
SM7675
SM7675P
SM8635
SM8635P
SM8650Q
SM8750P
Smart Audio 400 Platform
Snapdragon 4 Gen 1 Mobile Platform
Snapdragon 4 Gen 2 Mobile Platform
Snapdragon 460 Mobile Platform
Snapdragon 480 5G Mobile Platform
Snapdragon 480+ 5G Mobile Platform
Snapdragon 6 Gen 1 Mobile Platform
Snapdragon 6 Gen 3 Mobile Platform
Snapdragon 6 Gen 4 Mobile Platform
Snapdragon 662 Mobile Platform
Snapdragon 680 4G Mobile Platform
Snapdragon 685 4G Mobile Platform
Snapdragon 695 5G Mobile Platform
Snapdragon 7s Gen 3 Mobile Platform
Snapdragon 8 Elite
Snapdragon 8 Elite Gen 5
Snapdragon 8 Gen 3 Mobile Platform
Snapdragon AR1 Gen 1 Platform
Snapdragon AR1+ Gen 1 Platform
Snapdragon W5+ Gen 1 Wearable Platform
Snapdragon X65 5G Modem-RF System
Snapdragon XR2 5G Platform
Snapdragon XR2+ Gen 1 Platform
SRV1H
SRV1M
SW5100
SW5100P
SW6100
SW6100P
SXR2230P
SXR2250P
SXR2330P
SXR2350P
Themisto
WCD9335
WCD9370
WCD9375
WCD9378
WCD9380
WCD9385
WCD9390
WCD9395
WCN3910
WCN3950
WCN3980
WCN3988
WCN6450
WCN6650
WCN6755
WCN7860
WCN7861
WCN7880
WCN7881
WSA8810
WSA8815
WSA8830
WSA8835
WSA8840
WSA8845
WSA8845H
QCA6174A
QCA6574AU
SA6155P
SA8620P
SA9000P
WSA8832
Software vendor:
Qualcomm

Description

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in Graphics. A local application can execute arbitrary code.


Remediation

Install security update from vendor's website.

External links