Memory corruption during dynamic process creation call when client is only passing address and length of shell binary.
History

Tue, 03 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 03 Jun 2025 06:00:00 +0000

Type Values Removed Values Added
Description Memory corruption during dynamic process creation call when client is only passing address and length of shell binary.
Title Untrusted Pointer Dereference in DSP Service
Weaknesses CWE-822
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published: 2025-06-03T05:53:03.272Z

Updated: 2025-06-04T03:56:01.717Z

Reserved: 2024-12-18T09:50:08.935Z

Link: CVE-2025-21486

cve-icon Vulnrichment

Updated: 2025-06-03T14:56:49.824Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-03T06:15:26.590

Modified: 2025-06-04T14:54:33.783

Link: CVE-2025-21486

cve-icon Redhat

No data.